Kaspersky announces BlueNoroff's attacks targeting executives using Windows and macOS with AI-driven tools.
Tokyo, November 18, 2025 - (JCN Newswire) - Kaspersky's Global Research and Analysis Team (GReAT) has announced two types of advanced persistent threat campaigns, "GhostCall" and "GhostHire," as the latest APT activities by BlueNoroff.
These attacks have been continuously occurring since at least April 2025, targeting Web3 and cryptocurrency organizations in countries including India, Turkey, and Australia, as well as in Europe and Asia.
BlueNoroff is a subsidiary of the notorious Lazarus Group and is continuously expanding its representative campaign, "SnatchCrypto." SnatchCrypto is a financially motivated attack targeting the cryptocurrency industry worldwide.
The newly emerged campaigns, GhostCall and GhostHire, utilize new infiltration techniques and customized malware to compromise blockchain developers and executives.

Inquiry about this news
Contact Us Online




