Securelist
BlueNoroff Launches New Campaigns Targeting Crypto Professionals
First seen 2 Dec 2025, 18:33 UTC
•


•30.1
Export
Article Content
Browse articles
North Korea-aligned threat actor BlueNoroff has initiated two new campaigns, GhostCall and GhostHire, targeting fintech executives and Web3 developers. These campaigns utilize social engineering tactics on platforms like Telegram to deliver multi-stage malware targeting both macOS and Windows systems, with a focus on cryptocurrency theft and espionage.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
Bybit Sues North Korea Over $1.5 Billion Crypto Theft
North Korean Hackers Target macOS Users in Cryptocurrency Theft Campaign
BlueNoroff Targets Cryptocurrency Executives with AI-Enhanced Fake Zoom Attacks
Bitrefill Cyberattack Linked to North Korea's Lazarus Group Exposes Customer Data
North Korean BlueNoroff Uses AI for Sophisticated Zoom Phishing Attacks