Close Menu
economyuae.comeconomyuae.com
    What's Hot

    Avoid the Spam Folder: Email Deliverability Tips You Can’t Ignore

    March 26, 2026

    Seasonal Email Strategies That Drive Sales Without Feeling “Salesy”

    February 18, 2026

    How Lily Launched a Custom Clothing Brand Alongside a Full-Time Job

    February 16, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    economyuae.comeconomyuae.com
    Subscribe
    • Home
    • MARKET
    • STARTUPS
    • BUSINESS
    • ECONOMY
    • INTERVIEWS
    • MAGAZINE
    economyuae.comeconomyuae.com
    Home » Kaspersky exposes new BlueNoroff campaigns targeting Web3 firms
    BUSINESS

    Kaspersky exposes new BlueNoroff campaigns targeting Web3 firms

    Arabian Media staffBy Arabian Media staffOctober 30, 2025No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Security Analyst Summit in Thailand

    At the Security Analyst Summit in Thailand, Kaspersky’s Global Research and Analysis Team (GReAT) revealed the latest wave of BlueNoroff APT activity through two newly identified campaigns — GhostCall and GhostHire. The sophisticated operations, active since at least April 2025, have been targeting Web3 and cryptocurrency organisations across India, Turkiye, Australia, and multiple countries in Europe and Asia.

    BlueNoroff, a subdivision of the notorious Lazarus Group, has expanded its long-running SnatchCrypto campaign — a financially motivated initiative targeting the global crypto industry. The new GhostCall and GhostHire operations employ advanced infiltration techniques and custom-built malware designed to compromise blockchain developers and executives on macOS and Windows systems through a unified command-and-control infrastructure.

    The GhostCall campaign primarily targets macOS users, beginning with highly personalised social engineering attacks. Threat actors initiate contact through Telegram, impersonating venture capitalists and, in some cases, using compromised accounts of real entrepreneurs to promote false investment or partnership opportunities. Victims are invited to fake investment meetings on phishing websites that mimic Zoom or Microsoft Teams, where they are prompted to “update” their client — triggering the download of a malicious script.

    “This campaign relied on deliberate and carefully planned deception. Attackers replayed videos of previous victims during staged meetings to make the interaction appear like a real call and manipulate new targets. The data collected in this process is then used not only against the initial victim but also exploited to enable subsequent and supply-chain attacks, leveraging established trust relationships to compromise a broader range of organisations and users,” comments Sojun Ryu, security researcher at Kaspersky GReAT.

    The investigation revealed seven multi-stage execution chains, four of which were previously unknown, distributing customised payloads such as crypto stealers, browser credential stealers, secrets stealers, and Telegram credential stealers.

    In contrast, the GhostHire campaign targets blockchain developers through fake recruitment schemes. Posing as recruiters, attackers send victims GitHub repositories containing malware disguised as coding assessments. The campaign shares infrastructure and tools with GhostCall but relies on Telegram bots to deliver ZIP files or GitHub links with short completion deadlines. Once executed, the malware installs itself based on the operating system, providing attackers with persistent access.

    The use of generative AI has significantly enhanced BlueNoroff’s ability to scale and refine its attack methodologies. The group has adopted new programming languages, introduced additional malware features, and leveraged AI to analyze stolen data and identify high-value targets.

    “Since its previous campaigns, the threat actor’s targeting strategy has evolved beyond simple cryptocurrency and browser credential theft. The use of generative AI has significantly accelerated this process, enabling easier malware development with reduced operational overhead. This AI-driven approach helps to fill the gaps in available information, enabling more focused targeting. By combining compromised data with AI’s analytical capabilities, the scope of these attacks has expanded. We hope our research will contribute to preventing further harm,” comments Omar Amin, senior security researcher at Kaspersky GReAT.

    To defend against campaigns like GhostCall and GhostHire, Kaspersky recommends:

    • Verifying all investment or recruitment proposals and confirming the identity of contacts via trusted corporate channels.

    • Treating all unsolicited communication with caution, even from known contacts, as their accounts may be compromised.

    • Using comprehensive security solutions such as Kaspersky Next, which provides EDR/XDR capabilities for real-time protection and visibility.

    • Leveraging managed services like Kaspersky Managed Detection and Response (MDR), Incident Response, and Compromise Assessment to strengthen security operations.

    • Equipping InfoSec teams with Kaspersky Threat Intelligence for actionable insights and early risk detection.

    Kaspersky’s latest findings underline the growing convergence of AI and cybercrime — and the escalating risks facing the Web3 and digital asset sectors.






    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleClient Challenge
    Next Article MENA IPO activity rises as 11 listings raise $700m in Q3
    Arabian Media staff
    • Website

    Related Posts

    Dubai to implement mandatory marine traffic management plan

    December 15, 2025

    Here’s what to expect this week

    December 15, 2025

    IHC raises stake in Invictus Investment to about 40%

    December 15, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    10 Trends From Year 2020 That Predict Business Apps Popularity

    January 20, 2021

    Shipping Lines Continue to Increase Fees, Firms Face More Difficulties

    January 15, 2021

    Qatar Airways Helps Bring Tens of Thousands of Seafarers

    January 15, 2021

    Subscribe to Updates

    Your weekly snapshot of business, innovation, and market moves in the Arab world.

    Advertisement

    Economy UAE is your window into the pulse of the Arab world’s economy — where business meets culture, and ambition drives innovation.

    Facebook X (Twitter) Instagram Pinterest YouTube
    Top Insights

    Top UK Stocks to Watch: Capita Shares Rise as it Unveils

    January 15, 2021
    8.5

    Digital Euro Might Suck Away 8% of Banks’ Deposits

    January 12, 2021

    Oil Gains on OPEC Outlook That U.S. Growth Will Slow

    January 11, 2021
    Get Informed

    Subscribe to Updates

    Your weekly snapshot of business, innovation, and market moves in the Arab world.

    @2025 copyright by Arabian Media Group
    • Home
    • Markets
    • Stocks
    • Funds
    • Buy Now

    Type above and press Enter to search. Press Esc to cancel.