GhostCall is a social-engineering-driven malware campaign tracked by Kaspersky and attributed to BlueNoroff, also known as APT38 and TA444, a financially motivated subgroup of the Lazarus Group linked in the reporting to North Korea. It targets executives, Web3 developers, blockchain professionals, and in related reporting also open-source software maintainers. In GhostCall, operators impersonate venture capitalists or startup founders seeking to invest in blockchain projects and build trust through Telegram, LinkedIn, and fake video meetings on Zoom or Microsoft Teams. Victims are then prompted to install a supposed update or plugin to fix meeting quality or compatibility issues; executing it initiates a multi-stage infection chain.
Reported GhostCall-associated payloads and implants include DownTroy, CosmicDoor, and Rootroy. These implants are described as performing credential theft, keylogging, persistence, and broader reconnaissance. The malware searches for crypto wallet data, SSH keys, project credentials, and other sensitive project information, and includes exfiltration routines to send stolen data to attacker-controlled servers. Reporting states that exfiltrated data is often obfuscated with custom encryption and hexadecimal encoding. The campaign targets both macOS and Windows systems, and the broader malware set used in related activity has been written in Go, Rust, Nim, and AppleScript.
The reporting describes GhostCall as using multiple staging layers, dynamic command-and-control switching, and dormant behavior until crypto-related directories or developer tools are detected, indicating a focus on operational stealth. Huntress and Kaspersky documented the campaign, and later reporting states that the compromise of Axios npm maintainer Jason Saayman showed extensive overlap with GhostCall tradecraft. In that incident, a fake company approach, branded Slack workspace, and bogus Microsoft Teams update led to deployment of a remote access trojan, theft of npm credentials, and publication of trojanized Axios package versions 1.14.1 and 0.30.4 containing the WAVESHAPER.V2 implant. High-confidence associations in the provided content therefore link GhostCall to BlueNoroff social engineering, fake meeting software updates, credential theft, crypto-focused targeting, and supply-chain-adjacent intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"The axios attack is an extension of the GhostCall campaign by BlueNoroff" published by Kaspersky.
"Researchers Expose GhostCall and GhostHire: BlueNoroff's New Malware Chains"
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a named campaign associated with BlueNoroff; no specific malware functionality is described in the content.
A remote access trojan associated with the social engineering campaign attributed to UNC1069/BlueNoroff, used after a fake update prompt during a fraudulent Microsoft Teams call.
GhostCall is a modular, cross-platform malware campaign used by BlueNoroff to target blockchain and Web3 professionals via fake investor meetings. It delivers multi-stage implants for credential theft, keylogging, persistence, and exfiltration of sensitive data, with advanced stealth and dynamic C2 switching.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.