Executive Summary
In October 2025, cybersecurity researchers uncovered new attack chains, GhostCall and GhostHire, attributed to BlueNoroff—a sub-group of North Korea's Lazarus Group—targeting the Web3 and blockchain sectors. The campaigns form part of SnatchCrypto, an ongoing operation active since 2017, characterized by sophisticated spear-phishing, malware-laden documents, and social engineering tactics to infiltrate cryptocurrency firms and financial technology startups. Once initial access is gained, attackers deploy custom malware, bypass defenses, and ultimately exfiltrate sensitive data and digital assets, resulting in significant cryptocurrency thefts and disruption across targeted organizations.
This campaign is especially concerning amid a surge of advanced persistent threats exploiting trust gaps in rapidly evolving blockchain and cryptocurrency environments. Regulators and cybersecurity teams are on high alert as major financial losses and reputational impacts drive urgency for improved controls, detection, and Zero Trust strategies.
Why This Matters Now
BlueNoroff's recent campaigns demonstrate a growing sophistication in targeting digital asset infrastructures by nation-state actors, leveraging deceptive techniques and custom malware. As Web3 adoption expands and cryptocurrency valuations remain volatile, organizations face urgent risks of direct financial theft, regulatory scrutiny, and supply-chain exploitation.
Attack Path Analysis
The BlueNoroff sub-group initiated the attack by compromising an employee or system within a cryptocurrency or Web3 organization, likely via phishing or exploiting exposed cloud services. After gaining access, they escalated privileges to exploit credential weaknesses or misconfigured permissions, then moved laterally across internal cloud workloads or Kubernetes clusters to access sensitive assets. The attackers established command and control using covert communication and potentially leveraged encrypted outbound traffic. Through these channels, stolen assets or information were exfiltrated using encrypted or stealthy mechanisms. The operation culminated in theft of cryptocurrency assets and possible disruptive impacts on business operations.
Kill Chain Progression
Initial Compromise
Description
Attackers gained an initial foothold, possibly via phishing, malicious attachments, or exploiting exposed cloud services or stolen API keys targeting employees in Web3 organizations.
Related CVEs
CVE-2025-0411
CVSS 7.8A vulnerability in 7-Zip allows attackers to create archives that, when unpacked, do not inherit the Mark-of-the-Web (MOTW) flag, potentially enabling malicious code execution.
Affected Products:
Igor Pavlov 7-Zip – < 21.07
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
User Execution: Malicious File
Command and Scripting Interpreter
Valid Accounts
Obfuscated Files or Information
Email Collection
Exfiltration Over C2 Channel
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Access to Systems
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 10
CISA ZTMM 2.0 – Contextual Authentication
Control ID: Identity and Access Management: Contextual Authentication
NIS2 Directive – Security of Network and Information Systems
Control ID: Article 21(2)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
BlueNoroff's SnatchCrypto operations directly target financial institutions handling cryptocurrency transactions, requiring enhanced egress security and threat detection capabilities against North Korean APT groups.
Computer Software/Engineering
Web3 and blockchain software companies face sophisticated social engineering through GhostHire campaigns, necessitating zero trust segmentation and anomaly detection for developer environments.
Investment Banking/Venture
Cryptocurrency investment firms are prime targets for BlueNoroff's multi-year SnatchCrypto campaign, requiring multicloud visibility and encrypted traffic protection for digital asset transactions.
Computer/Network Security
Cybersecurity firms analyzing blockchain threats need enhanced east-west traffic security and inline IPS capabilities to detect and prevent sophisticated North Korean threat actor infiltration.
Sources
- Researchers Expose GhostCall and GhostHire: BlueNoroff's New Malware Chainshttps://thehackernews.com/2025/10/researchers-expose-ghostcall-and.htmlVerified
- Kaspersky: BlueNoroff targets executives on Windows and macOS using AI-driven toolshttps://www.kaspersky.com/about/press-releases/kaspersky-bluenoroff-targets-executives-on-windows-and-macos-using-ai-driven-toolsVerified
- Kaspersky finds BlueNoroff APT actor disguised itself as VC firms to deliver new malwarehttps://usa.kaspersky.com/about/press-releases/kaspersky-finds-bluenoroff-apt-actor-disguised-itself-as-vc-firms-to-deliver-new-malwareVerified
- Snatch that crypto: BlueNoroff threat actor drains cryptocurrency startups’ accountshttps://www.kaspersky.com/about/press-releases/snatch-that-crypto-bluenoroff-threat-actor-drains-cryptocurrency-startups-accountsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Comprehensive zero trust segmentation, enforcement of least privilege network and identity policies, encrypted traffic controls, and egress filtering would have critically constrained BlueNoroff's ability to pivot internally, establish covert C2, and exfiltrate assets, reducing the blast radius and enabling earlier detection or prevention.
Control: Cloud Firewall (ACF)
Mitigation: Restricts attack surface by enforcing inbound policy at the cloud perimeter.
Control: Zero Trust Segmentation
Mitigation: Prevents privilege escalation through enforced least-privilege and microsegmentation.
Control: East-West Traffic Security
Mitigation: Blocks unauthorized intra-cloud traffic and detects abnormal service-to-service connections.
Control: Inline IPS (Suricata)
Mitigation: Detects and blocks C2 traffic using signature-based and anomaly detection.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents unauthorized data egress and enforces outbound policies.
Early detection and containment of abnormal behaviors minimizes operational and financial losses.
Impact at a Glance
Affected Business Functions
- Financial Transactions
- Client Communications
- Software Development
Estimated downtime: 7 days
Estimated loss: $5,000,000
Potential exposure of sensitive financial data, client information, and intellectual property related to blockchain and cryptocurrency operations.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce zero trust segmentation across all cloud workloads, with identity-based microsegmentation policies to eliminate lateral movement paths.
- • Deploy comprehensive east-west and egress traffic security, including deep packet inspection and application-aware filtering, across multi-cloud networks.
- • Integrate cloud-native firewalls and inline IPS to block known exploits, command and control techniques, and prevent exposure of critical assets.
- • Implement centralized, real-time threat detection and anomaly response to rapidly contain suspicious activity and pre-empt data exfiltration attempts.
- • Continuously audit and enforce least-privilege IAM roles and network policies to reduce the risk of privilege escalation and unauthorized cloud access.



