Close Menu
economyarab.comeconomyarab.com
    What's Hot

    Special ferry, abra and water taxi packages unveiled

    December 1, 2025

    Tenable’s Mark Thurmond on Black Hat, cybersecurity and exposure management

    December 1, 2025

    Watch fireworks, parade, activities here

    December 1, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    economyarab.comeconomyarab.com
    Subscribe
    • Home
    • Economy
    • Market
    • Finance
    • Startups
    • Interviews
    • Magazine
    • Arab 100
    economyarab.comeconomyarab.com
    Home » Kaspersky exposes new BlueNoroff campaigns targeting Web3 firms
    Finance

    Kaspersky exposes new BlueNoroff campaigns targeting Web3 firms

    Arabian Media staffBy Arabian Media staffOctober 30, 2025No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Security Analyst Summit in Thailand

    At the Security Analyst Summit in Thailand, Kaspersky’s Global Research and Analysis Team (GReAT) revealed the latest wave of BlueNoroff APT activity through two newly identified campaigns — GhostCall and GhostHire. The sophisticated operations, active since at least April 2025, have been targeting Web3 and cryptocurrency organisations across India, Turkiye, Australia, and multiple countries in Europe and Asia.

    BlueNoroff, a subdivision of the notorious Lazarus Group, has expanded its long-running SnatchCrypto campaign — a financially motivated initiative targeting the global crypto industry. The new GhostCall and GhostHire operations employ advanced infiltration techniques and custom-built malware designed to compromise blockchain developers and executives on macOS and Windows systems through a unified command-and-control infrastructure.

    The GhostCall campaign primarily targets macOS users, beginning with highly personalised social engineering attacks. Threat actors initiate contact through Telegram, impersonating venture capitalists and, in some cases, using compromised accounts of real entrepreneurs to promote false investment or partnership opportunities. Victims are invited to fake investment meetings on phishing websites that mimic Zoom or Microsoft Teams, where they are prompted to “update” their client — triggering the download of a malicious script.

    “This campaign relied on deliberate and carefully planned deception. Attackers replayed videos of previous victims during staged meetings to make the interaction appear like a real call and manipulate new targets. The data collected in this process is then used not only against the initial victim but also exploited to enable subsequent and supply-chain attacks, leveraging established trust relationships to compromise a broader range of organisations and users,” comments Sojun Ryu, security researcher at Kaspersky GReAT.

    The investigation revealed seven multi-stage execution chains, four of which were previously unknown, distributing customised payloads such as crypto stealers, browser credential stealers, secrets stealers, and Telegram credential stealers.

    In contrast, the GhostHire campaign targets blockchain developers through fake recruitment schemes. Posing as recruiters, attackers send victims GitHub repositories containing malware disguised as coding assessments. The campaign shares infrastructure and tools with GhostCall but relies on Telegram bots to deliver ZIP files or GitHub links with short completion deadlines. Once executed, the malware installs itself based on the operating system, providing attackers with persistent access.

    The use of generative AI has significantly enhanced BlueNoroff’s ability to scale and refine its attack methodologies. The group has adopted new programming languages, introduced additional malware features, and leveraged AI to analyze stolen data and identify high-value targets.

    “Since its previous campaigns, the threat actor’s targeting strategy has evolved beyond simple cryptocurrency and browser credential theft. The use of generative AI has significantly accelerated this process, enabling easier malware development with reduced operational overhead. This AI-driven approach helps to fill the gaps in available information, enabling more focused targeting. By combining compromised data with AI’s analytical capabilities, the scope of these attacks has expanded. We hope our research will contribute to preventing further harm,” comments Omar Amin, senior security researcher at Kaspersky GReAT.

    To defend against campaigns like GhostCall and GhostHire, Kaspersky recommends:

    • Verifying all investment or recruitment proposals and confirming the identity of contacts via trusted corporate channels.

    • Treating all unsolicited communication with caution, even from known contacts, as their accounts may be compromised.

    • Using comprehensive security solutions such as Kaspersky Next, which provides EDR/XDR capabilities for real-time protection and visibility.

    • Leveraging managed services like Kaspersky Managed Detection and Response (MDR), Incident Response, and Compromise Assessment to strengthen security operations.

    • Equipping InfoSec teams with Kaspersky Threat Intelligence for actionable insights and early risk detection.

    Kaspersky’s latest findings underline the growing convergence of AI and cybercrime — and the escalating risks facing the Web3 and digital asset sectors.






    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleLucid and NVIDIA partner to deliver Level 4 autonomous vehicles
    Next Article MENA IPO activity rises as 11 listings raise $700m in Q3
    Arabian Media staff
    • Website

    Related Posts

    Special ferry, abra and water taxi packages unveiled

    December 1, 2025

    Tenable’s Mark Thurmond on Black Hat, cybersecurity and exposure management

    December 1, 2025

    Watch fireworks, parade, activities here

    December 1, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    10 Trends From Year 2020 That Predict Business Apps Popularity

    January 20, 2021

    Shipping Lines Continue to Increase Fees, Firms Face More Difficulties

    January 15, 2021

    Qatar Airways Helps Bring Tens of Thousands of Seafarers

    January 15, 2021

    Subscribe to Updates

    Your weekly snapshot of business, innovation, and market moves in the Arab world.

    Economy Arab is your window into the pulse of the Arab world’s economy — where business meets culture, and ambition drives innovation.

    Facebook X (Twitter) Instagram Pinterest YouTube
    Top Insights

    Top UK Stocks to Watch: Capita Shares Rise as it Unveils

    January 15, 2021
    8.5

    Digital Euro Might Suck Away 8% of Banks’ Deposits

    January 12, 2021

    Oil Gains on OPEC Outlook That U.S. Growth Will Slow

    January 11, 2021
    Get Informed

    Subscribe to Updates

    Your weekly snapshot of business, innovation, and market moves in the Arab world.

    @2025 copyright by Arabian Media Group
    • Home
    • About Us

    Type above and press Enter to search. Press Esc to cancel.