North Korea-aligned threat actor BlueNoroff, also known as APT38, has launched two new campaigns, GhostCall and GhostHire, targeting executives, Web3 developers, and blockchain professionals across multiple countries. The campaigns use sophisticated social engineering tactics, such as fake investor meetings and bogus recruiter tests, to lure victims via platforms like Telegram and LinkedIn. Victims are tricked into downloading malicious files during staged video calls or through fraudulent meeting invitations, leading to the deployment of multi-stage, cross-platform malware on both macOS and Windows systems. The malware, written in languages such as Go, Rust, Nim, and AppleScript, includes payloads like DownTroy, CosmicDoor, Rootroy, and others, each designed for credential theft, keylogging, persistence, and further compromise.
GhostCall primarily targets tech firm and venture capital executives, especially in countries such as Japan, Italy, France, Sweden, Spain, Turkey, India, Hong Kong, and Singapore, by exploiting fake investment meetings to deliver AppleScript-based malware. GhostHire focuses on Web3 developers and the broader blockchain industry, distributing malicious ZIP files that infect Windows machines with additional payloads, including a Rust-based loader. Researchers have observed that BlueNoroff's adoption of generative artificial intelligence has accelerated the development of their cross-platform malware, underscoring an evolution in both technical sophistication and targeting strategy within the ongoing SnatchCrypto operation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On October 29, 2025, reporting based on Kaspersky Securelist revealed that BlueNoroff had reemerged with two social-engineering campaigns, GhostCall and GhostHire, as part of its long-running SnatchCrypto activity. Researchers said the operations showed increased use of modular, cross-platform malware, dynamic command-and-control switching, multiple programming languages, and tailored targeting of the blockchain sector.
In a parallel campaign dubbed GhostCall, BlueNoroff targeted executives at technology firms and venture capital companies across multiple countries using Telegram, LinkedIn, and fake meeting or investor lures tied to Zoom, Teams, and other platforms. Victims were tricked into downloading malicious updates or SDKs that led to macOS compromise and deployment of payloads including DownTroy, CosmicDoor, and ZoomClutch/TeamsClutch variants.
Kaspersky assessed with medium confidence that the Telegram- and GitHub-based GhostHire workflow began no later than April 2025. The campaign used fake job offers, coding tests, and malicious ZIP archives to target Web3 developers and blockchain professionals with malware aimed at stealing credentials, wallet data, SSH keys, and project information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.