logo

Crypto wasted: BlueNoroff’s ghost mirage of funding and jobs

ID: e7c4f684-9a00-53a4-868a-0345d666b5b5

STIX ID: report--e7c4f684-9a00-53a4-868a-0345d666b5b5

Feed Name: Securelist by Kaspersky

Threat Score
88/100

Date Published: 2025-10-28

Date Updated: 2026-07-16

Author: Sojun Ryu, Omar Amin

...
...

This Kaspersky threat intelligence report attributes two coordinated BlueNoroff operations—GhostCall and GhostHire—that target Web3/blockchain executives and developers using tailored social‑engineering (fake calls, recruiter assessments), Telegram bots, malicious GitHub dependencies, and multi‑stage cross‑platform malware (macOS, Windows, Linux). The actors employ sophisticated techniques (TCC DB bypass, process injection, UAC bypass, loaders/injectors written in Nim/C++/Go/Rust/Swift), a modular stealer suite (SilentSiphon), numerous C2 domains and file hosting services, and provided extensive IoCs and telemetry tying activity to BlueNoroff and financial motives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.