Skip to content
February 9, 2026
Mochiai.blog
Mochiai.blog
Random Article
  • Home
  • Cybersecurity
  • BlueNoroff reemerges with new campaigns for crypto theft and espionage
Categories Cybersecurity

BlueNoroff reemerges with new campaigns for crypto theft and espionage

  • By Shweta Sharma
  • Estimated read time 1 min read
  • October 29, 2025
BlueNoroff reemerges with new campaigns for crypto theft and espionage

Researchers noted that the new campaigns highlight BlueNoroff’s shift toward modular malware, cross-platform threats, and highly tailored targeting of the blockchain space. The malware samples were found written in multiple programming languages, including Go, Rust, Nim, and AppleScript, reflecting an added technical layer in the group’s operations.

Compromise through fake “investor meetings”

In the GhostCall campaign, BlueNoroff poses as venture capitalists or startup founders seeking to “invest” in blockchain projects. The attackers set up fake video meetings via platforms like Zoom or Teams, luring victims into a false sense of legitimacy.

During or after these calls, the victim is asked to install a supposed “update” or “plugin” to improve connection quality. The file, of course, is malicious–triggering a chain of implants such as DownTroy, CosmicDoor, and Rootroy, each performing specialized tasks like credential theft, keylogging, or persistence.

Tags cryptocurrency theft espionage campaign
← Best power station deal: Best-ever price on Jackery Explorer 1000 v2 → Discover Practical AI Tactics for GRC — Join the Free Expert Webinar

Loading...

Categories

  • AI Medical
  • AI Reasoning Model
  • Artificial intelligence
  • Best Exam for AI
  • Cybersecurity
  • Machine Learning
  • Programming & Tech
  • Technology
  • Uncategorized
  • VM

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • April 2016

Copyright © 2026
 - Powered by Magze.