{"id":433743,"date":"2025-10-28T16:22:42","date_gmt":"2025-10-28T13:22:42","guid":{"rendered":"https:\/\/menatech.net\/en\/?p=433743"},"modified":"2025-11-11T17:02:25","modified_gmt":"2025-11-11T14:02:25","slug":"hacker-group-targeting-crypto-executives-with-ai-driven-tools-warns-kaspersky","status":"publish","type":"post","link":"https:\/\/menatech.net\/en\/hacker-group-targeting-crypto-executives-with-ai-driven-tools-warns-kaspersky\/","title":{"rendered":"Hacker group targeting crypto executives with AI-driven tools, warns Kaspersky"},"content":{"rendered":"<p style=\"font-weight: 400;\">Kaspersky\u2019s Global Research and Analysis Team (GReAT) revealed the latest BlueNoroff APT activity through two highly targeted malicious campaigns, \u2018GhostCall\u2019 and \u2018GhostHire\u2019. The ongoing operations have targeted Web3 and cryptocurrency organizations across India, Turkey, Australia, and other countries in Europe and Asia since at least April 2025.\u00a0The announcement was made at the <a href=\"https:\/\/thesascon.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Security Analyst Summit<\/a> in Thailand, of which MENA TECH is the exclusive Middle East media partner.<\/p>\n<p>BlueNoroff, a branch of the notorious Lazarus group, continues to expand its signature \u2018SnatchCrypto\u2019 campaign,\u00a0a financially\u00a0driven operation targeting the global crypto industry. The newly revealed GhostCall and GhostHire campaigns use new infiltration methods and customized malware to compromise blockchain developers and executives. These attacks mainly target macOS and Windows systems and are managed through a centralized command-and-control infrastructure.<\/p>\n<p style=\"font-weight: 400;\">The GhostCall campaign targets macOS devices, beginning with a highly sophisticated, personalized social engineering attack. The attackers contact victims through Telegram, impersonating venture capitalists and sometimes using compromised accounts of real entrepreneurs and startup founders to promote investment or partnership opportunities. The victims are invited to fake investment meetings on phishing sites that mimic Zoom or Microsoft Teams, during which they are prompted to \u201cupdate\u201d their client to resolve an audio issue. This action downloads a malicious script and installs malware on the device.<\/p>\n<p style=\"font-weight: 400;\"><em>\u201cThis campaign relied on deliberate and carefully planned deception. Attackers replayed videos of previous victims during staged meetings to make the interaction appear like a real call and manipulate new targets. The data collected in this process is then used not only against the initial victim but also exploited to enable subsequent and supply-chain attacks, leveraging established trust relationships to compromise a broader range of organizations and users,\u201d <\/em>comments Sojun Ryu, security researcher at Kaspersky GReAT.<\/p>\n<p style=\"font-weight: 400;\">Attackers used seven multi-stage execution chains, four of which were previously unseen, to distribute a variety of new customized payloads, including crypto stealers, browser credential stealers, secrets stealers, and Telegram credential stealers.\u00a0<\/p>\n<p style=\"font-weight: 400;\"><img decoding=\"async\" class=\"aligncenter size-medium_large wp-image-433744 lazyload\" data-src=\"https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/GhostCall-campaign-attack-flow-W-768x227.png\" alt=\"\" width=\"768\" height=\"227\" data-srcset=\"https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/GhostCall-campaign-attack-flow-W-768x227.png 768w, https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/GhostCall-campaign-attack-flow-W-300x89.png 300w, https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/GhostCall-campaign-attack-flow-W-1024x303.png 1024w, https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/GhostCall-campaign-attack-flow-W-1536x454.png 1536w, https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/GhostCall-campaign-attack-flow-W-2048x606.png 2048w\" data-sizes=\"auto\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 768px; --smush-placeholder-aspect-ratio: 768\/227;\" data-original-sizes=\"(max-width: 768px) 100vw, 768px\" \/><\/p>\n<p style=\"font-weight: 400;\">In the GhostHire campaign, the APT targets blockchain developers by posing as recruiters. Victims are deceived into downloading and executing a GitHub repository containing malware, presented as a skill assessment. GhostHire shares its infrastructure and tools with the GhostCall campaign, but instead of using video calls, it focuses on approaching hands-on developers and engineers through fake recruitment efforts. After initial contact, victims are added to a Telegram bot that delivers either a ZIP file or a GitHub link, along with a short deadline to complete the task. Once run, the malware installs itself on the victim\u2019s machine, tailored for the operating system.<\/p>\n<p style=\"font-weight: 400;\"><img decoding=\"async\" class=\"aligncenter size-medium_large wp-image-433745 lazyload\" data-src=\"https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/GhostHire-campaign-attack-flow-W-768x192.png\" alt=\"\" width=\"768\" height=\"192\" data-srcset=\"https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/GhostHire-campaign-attack-flow-W-768x192.png 768w, https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/GhostHire-campaign-attack-flow-W-300x75.png 300w, https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/GhostHire-campaign-attack-flow-W-1024x256.png 1024w, https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/GhostHire-campaign-attack-flow-W-1536x384.png 1536w, https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/GhostHire-campaign-attack-flow-W-2048x512.png 2048w\" data-sizes=\"auto\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 768px; --smush-placeholder-aspect-ratio: 768\/192;\" data-original-sizes=\"(max-width: 768px) 100vw, 768px\" \/><\/p>\n<p style=\"font-weight: 400;\">The use of generative AI has enabled BlueNoroff to accelerate malware development and refine its attack methods. The attackers introduced new programming languages and added extra features, making detection and analysis harder. It also helps the actor manage and grow its operations, increasing both the complexity and extent of attacks.\u00a0<\/p>\n<p style=\"font-weight: 400;\"><em>\u201cSince its previous campaigns, the threat actor\u2019s targeting strategy has evolved beyond simple cryptocurrency and browser credential theft. The use of generative AI has significantly accelerated this process, enabling easier malware development with reduced operational overhead. This AI-driven approach helps to fill the gaps in available information, enabling more focused targeting. By combining compromised data with AI\u2019s analytical capabilities, the scope of these attacks has expanded. We hope our research will contribute to preventing further harm,<\/em>\u201d comments Omar Amin, senior security researcher at Kaspersky GReAT.<\/p>\n<p style=\"font-weight: 400;\">More information, together with the indicators of compromise, is available in a report on <a href=\"https:\/\/securelist.com\/bluenoroff-apt-campaigns-ghostcall-and-ghosthire\/117842\/\" rel=\"nofollow noopener\" target=\"_blank\">Securelist.com<\/a>.<\/p>\n<p style=\"font-weight: 400;\">To stay protected from attacks such as GhostCall and GhostHire, organizations are advised to follow these best practices:<\/p>\n<ul>\n<li>Be cautious with generous offers and investment proposals. Verify the identity of every new contact, especially those reaching out via Telegram, LinkedIn, or other social platforms. Use verified and secure corporate channels for all sensitive communications.<\/li>\n<li>Consider the possibility that a trusted contact\u2019s account might be compromised. Confirm identities through alternative channels before opening any files or links, always ensuring you&#8217;re on an official domain. Do not run unverified scripts or commands to fix issues.<\/li>\n<li>To safeguard the company against various threats, utilize solutions from the <a href=\"https:\/\/www.kaspersky.com\/next\" rel=\"nofollow noopener\" target=\"_blank\">Kaspersky Next<\/a> product line that offer real-time protection, threat visibility, and the investigation and response capabilities of EDR and XDR for organizations of any size and industry. Based on your current needs and available resources, you can select the most appropriate product tier and easily upgrade to another as your cybersecurity requirements evolve.<\/li>\n<li>Adopt managed security services covering the entire incident management cycle \u2013 from threat identification to continuous protection and remediation.\u00a0 They help protect against evasive cyberattacks, investigate incidents, and provide additional expertise, even when a company lacks cybersecurity workers.<\/li>\n<li>Give your InfoSec professionals comprehensive visibility into cyber threats targeting your organization. The latest <a href=\"https:\/\/www.kaspersky.com\/enterprise-security\/threat-intelligence\" rel=\"nofollow noopener\" target=\"_blank\">Kaspersky Threat Intelligence<\/a> offers detailed and relevant context throughout the entire incident management cycle, helping them identify cyber risks promptly.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky\u2019s Global Research and Analysis Team (GReAT) revealed the latest BlueNoroff APT activity through two highly targeted malicious campaigns, \u2018GhostCall\u2019 and \u2018GhostHire\u2019. The ongoing operations have targeted Web3 and cryptocurrency organizations across India, Turkey, Australia, and other countries in Europe and Asia since at least April 2025.\u00a0The announcement was made at the Security Analyst Summit [&hellip;]<\/p>\n","protected":false},"author":254,"featured_media":433746,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":[],"meta":{"_acf_changed":false,"_breakdance_hide_in_design_set":false,"_breakdance_tags":"","footnotes":""},"categories":[29330],"tags":[29420,29380,29405,29382],"audience-intent":[],"content-types":[],"country":[],"entity":[],"persona":[],"class_list":["post-433743","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business","tag-crypto","tag-cybersecurity","tag-enterprise-news","tag-fintech"],"acf":[],"_links":{"self":[{"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/posts\/433743","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/users\/254"}],"replies":[{"embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/comments?post=433743"}],"version-history":[{"count":0,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/posts\/433743\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/media\/433746"}],"wp:attachment":[{"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/media?parent=433743"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/categories?post=433743"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/tags?post=433743"},{"taxonomy":"audience-intent","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/audience-intent?post=433743"},{"taxonomy":"content-types","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/content-types?post=433743"},{"taxonomy":"country","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/country?post=433743"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/entity?post=433743"},{"taxonomy":"format","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/format?post=433743"},{"taxonomy":"persona","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/persona?post=433743"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}