North Korea-linked BlueNoroff has been tied to two coordinated intrusion campaigns, GhostCall and GhostHire, aimed at blockchain developers, executives, managers, and venture capital contacts in the Web3 ecosystem as part of its broader SnatchCrypto activity. Researchers said GhostCall lured victims into fake Zoom or Microsoft Teams meetings arranged through Telegram and phishing domains, then tricked them into executing malicious AppleScript on macOS or clipboard-swapped commands on Windows. GhostHire used recruiter impersonation to deliver poisoned coding assignments through Telegram bots, GitHub repositories, and trojanized Go or TypeScript projects.
The operations used overlapping infrastructure and a broad malware toolkit spanning at least seven modular macOS infection chains, with families including DownTroy, ZoomClutch, TeamsClutch, CosmicDoor, RooTroy, RealTimeTroy, SneakMain, SysPhon, and SilentSiphon, alongside a keylogger. The actor expanded beyond earlier standalone malware into modular launchers, loaders, droppers, injectors, and stealers written in AppleScript, Go, Nim, Rust, Swift, Python, and C++, and also extended tooling to Windows and Linux in GhostHire. Investigators also observed the use of AI to refine social engineering and enhance images, while stolen webcam footage from victims was reportedly reused in later fake calls to make the scams more convincing; victims were identified across multiple countries, particularly in the Asia-Pacific region.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The research assessed with medium-high confidence that BlueNoroff was responsible for both campaigns based on overlapping infrastructure, malware families, tooling, targeting patterns, and continuity with earlier SnatchCrypto operations. The report also documented at least seven modular macOS infection chains and broader expansion of tooling to Windows and Linux.
Kaspersky reported that BlueNoroff was running two major campaigns, GhostCall and GhostHire, as part of its SnatchCrypto activity against blockchain developers, executives, managers, and related venture capital targets. The campaigns used fake Zoom or Microsoft Teams meetings, recruiter lures, Telegram, phishing domains, and poisoned coding projects to compromise victims across multiple countries, especially in APAC.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcearchive.md
Open sourcesecurelist.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.