BlueNoroff reemerges with new campaigns for crypto theft and espionage

BlueNoroff Reemerges with New Campaigns

North Korea-aligned threat actor BlueNoroff, also known as APT38 and TA444, has resurfaced with two new campaigns: "GhostCall" and "GhostHire".

These campaigns target executives, Web3 developers, and blockchain professionals, using social engineering tactics via platforms like Telegram and LinkedIn to deliver multi-stage malware chains.

BlueNoroff is believed to operate the long-running SnatchCrypto campaign, with GhostCall and GhostHire appearing to be the latest extensions.

Author's summary: BlueNoroff launches new crypto theft campaigns.

more

CSO Online CSO Online — 2025-10-29

More News