North Korean threat actor BlueNoroff, a sub-cluster of the Lazarus Group, has launched two sophisticated campaigns—GhostCall and GhostHire—targeting executives in the fintech, venture capital, and Web3 development sectors. According to Kaspersky and corroborated by multiple sources, GhostCall leverages social engineering via platforms like Telegram to lure technology and venture capital executives into fake investment meetings, ultimately tricking them into downloading malicious scripts disguised as Zoom updates. These scripts deploy infection chains on macOS devices, resulting in credential theft and system compromise. GhostHire, meanwhile, targets Web3 developers by inviting them to complete skill assessments through booby-trapped GitHub repositories, which deliver tailored malware payloads based on the victim's operating system. Both campaigns demonstrate BlueNoroff's evolving tactics, including the use of generative AI for malware development and a shift from macOS to Windows platforms.
Researchers note that these operations are part of BlueNoroff's broader, years-long SnatchCrypto campaign, which aims to steal cryptocurrency and financial data to fund the North Korean regime. The campaigns employ advanced social engineering, cross-platform malware, and innovative infection vectors, highlighting the group's increasing sophistication and adaptability. The targeting of high-value individuals in the fintech and Web3 sectors underscores the persistent threat posed by North Korean APTs to the global cryptocurrency ecosystem, with significant financial and reputational risks for affected organizations and individuals.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Kaspersky assessed that BlueNoroff is increasingly using generative AI to speed malware development and improve social-engineering content used in the GhostCall and GhostHire campaigns.
The report detailed that the campaigns now deliver malware across macOS, Windows, and Linux using tools such as DownTroy, CosmicDoor, RealTimeTroy, SilentSiphon, SysPhon, RooTroy, and SUGARLOADER, and that the actor's objectives have expanded beyond crypto theft to broader credential and data collection.
Kaspersky disclosed that BlueNoroff is running two active Web3-focused campaigns, GhostCall and GhostHire, under SnatchCrypto to steal cryptocurrency, credentials, and other sensitive data from executives and developers.
Researchers reported that BlueNoroff recently changed parts of its social-engineering approach, moving from fake Zoom meeting lures to Microsoft Teams-themed lures in the GhostCall campaign.
Kaspersky said the broader SnatchCrypto activity attributed to the Lazarus Group sub-cluster BlueNoroff has been active since at least 2017, forming the long-running basis for later GhostCall and GhostHire campaigns.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.