Close Menu
arabianfeature.comarabianfeature.com
    What's Hot

    How Saudi Arabia’s Night-Time Economy Takes Over During Holy Month

    March 2, 2026

    Best Luxury Property Projects Covered by Arabian Feature This Year

    February 27, 2026

    How to Get Featured on Arabian Feature as a Startup or CEO

    February 23, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    arabianfeature.comarabianfeature.com
    Subscribe
    • Home
    • CEOs
    • Women
    • AI & Tech
    • Magazine
    • Real Estate
    • Luxury
    • Feature
    arabianfeature.comarabianfeature.com
    Home » Kaspersky exposes new BlueNoroff campaigns targeting Web3 firms
    Feature

    Kaspersky exposes new BlueNoroff campaigns targeting Web3 firms

    Arabian Media staffBy Arabian Media staffOctober 30, 2025No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Security Analyst Summit in Thailand

    At the Security Analyst Summit in Thailand, Kaspersky’s Global Research and Analysis Team (GReAT) revealed the latest wave of BlueNoroff APT activity through two newly identified campaigns — GhostCall and GhostHire. The sophisticated operations, active since at least April 2025, have been targeting Web3 and cryptocurrency organisations across India, Turkiye, Australia, and multiple countries in Europe and Asia.

    BlueNoroff, a subdivision of the notorious Lazarus Group, has expanded its long-running SnatchCrypto campaign — a financially motivated initiative targeting the global crypto industry. The new GhostCall and GhostHire operations employ advanced infiltration techniques and custom-built malware designed to compromise blockchain developers and executives on macOS and Windows systems through a unified command-and-control infrastructure.

    The GhostCall campaign primarily targets macOS users, beginning with highly personalised social engineering attacks. Threat actors initiate contact through Telegram, impersonating venture capitalists and, in some cases, using compromised accounts of real entrepreneurs to promote false investment or partnership opportunities. Victims are invited to fake investment meetings on phishing websites that mimic Zoom or Microsoft Teams, where they are prompted to “update” their client — triggering the download of a malicious script.

    “This campaign relied on deliberate and carefully planned deception. Attackers replayed videos of previous victims during staged meetings to make the interaction appear like a real call and manipulate new targets. The data collected in this process is then used not only against the initial victim but also exploited to enable subsequent and supply-chain attacks, leveraging established trust relationships to compromise a broader range of organisations and users,” comments Sojun Ryu, security researcher at Kaspersky GReAT.

    The investigation revealed seven multi-stage execution chains, four of which were previously unknown, distributing customised payloads such as crypto stealers, browser credential stealers, secrets stealers, and Telegram credential stealers.

    In contrast, the GhostHire campaign targets blockchain developers through fake recruitment schemes. Posing as recruiters, attackers send victims GitHub repositories containing malware disguised as coding assessments. The campaign shares infrastructure and tools with GhostCall but relies on Telegram bots to deliver ZIP files or GitHub links with short completion deadlines. Once executed, the malware installs itself based on the operating system, providing attackers with persistent access.

    The use of generative AI has significantly enhanced BlueNoroff’s ability to scale and refine its attack methodologies. The group has adopted new programming languages, introduced additional malware features, and leveraged AI to analyze stolen data and identify high-value targets.

    “Since its previous campaigns, the threat actor’s targeting strategy has evolved beyond simple cryptocurrency and browser credential theft. The use of generative AI has significantly accelerated this process, enabling easier malware development with reduced operational overhead. This AI-driven approach helps to fill the gaps in available information, enabling more focused targeting. By combining compromised data with AI’s analytical capabilities, the scope of these attacks has expanded. We hope our research will contribute to preventing further harm,” comments Omar Amin, senior security researcher at Kaspersky GReAT.

    To defend against campaigns like GhostCall and GhostHire, Kaspersky recommends:

    • Verifying all investment or recruitment proposals and confirming the identity of contacts via trusted corporate channels.

    • Treating all unsolicited communication with caution, even from known contacts, as their accounts may be compromised.

    • Using comprehensive security solutions such as Kaspersky Next, which provides EDR/XDR capabilities for real-time protection and visibility.

    • Leveraging managed services like Kaspersky Managed Detection and Response (MDR), Incident Response, and Compromise Assessment to strengthen security operations.

    • Equipping InfoSec teams with Kaspersky Threat Intelligence for actionable insights and early risk detection.

    Kaspersky’s latest findings underline the growing convergence of AI and cybercrime — and the escalating risks facing the Web3 and digital asset sectors.






    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleParsons awarded $56m contract for Diriyah Phase 2 public realm development
    Next Article Lucid and NVIDIA partner to deliver Level 4 autonomous vehicles
    Arabian Media staff
    • Website

    Related Posts

    The 2026 Winter Olympics: Italy’s Moment on the World Stage

    February 17, 2026

    Riwaz Sajan: When Tradition Becomes the Language of the Heart

    February 12, 2026

    Top 100 Arab Founder in 2026: Powerful Entrepreneurs Building Global Brands

    January 16, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    10 Trends From Year 2020 That Predict Business Apps Popularity

    January 20, 2021

    Shipping Lines Continue to Increase Fees, Firms Face More Difficulties

    January 15, 2021

    Qatar Airways Helps Bring Tens of Thousands of Seafarers

    January 15, 2021

    Subscribe to Updates

    Get the best of Arab culture, lifestyle, and stories . Straight to your inbox. Subscribe to Arabian Feature and never miss a beat.

    Arabian Feature is your window into the heart of the Arab world. We bring you inspiring stories, fresh perspectives, and unique voices from across the region—covering culture, lifestyle, people, and progress. Bold, curious, and proudly Arab.

    Facebook X (Twitter) Instagram Pinterest YouTube
    Top Insights

    Top UK Stocks to Watch: Capita Shares Rise as it Unveils

    January 15, 2021
    8.5

    Digital Euro Might Suck Away 8% of Banks’ Deposits

    January 12, 2021

    Oil Gains on OPEC Outlook That U.S. Growth Will Slow

    January 11, 2021
    Get Informed

    Subscribe to Updates

    Get the best of Arab culture, lifestyle, and stories . Straight to your inbox. Subscribe to Arabian Feature and never miss a beat.

    @2025 copyright by Arabian Media Group
    • Home
    • About Us

    Type above and press Enter to search. Press Esc to cancel.