The Containment Era is here. →Explore

Executive Summary

In October 2025, cybersecurity researchers uncovered new attack chains, GhostCall and GhostHire, attributed to BlueNoroff—a sub-group of North Korea's Lazarus Group—targeting the Web3 and blockchain sectors. The campaigns form part of SnatchCrypto, an ongoing operation active since 2017, characterized by sophisticated spear-phishing, malware-laden documents, and social engineering tactics to infiltrate cryptocurrency firms and financial technology startups. Once initial access is gained, attackers deploy custom malware, bypass defenses, and ultimately exfiltrate sensitive data and digital assets, resulting in significant cryptocurrency thefts and disruption across targeted organizations.

This campaign is especially concerning amid a surge of advanced persistent threats exploiting trust gaps in rapidly evolving blockchain and cryptocurrency environments. Regulators and cybersecurity teams are on high alert as major financial losses and reputational impacts drive urgency for improved controls, detection, and Zero Trust strategies.

Why This Matters Now

BlueNoroff's recent campaigns demonstrate a growing sophistication in targeting digital asset infrastructures by nation-state actors, leveraging deceptive techniques and custom malware. As Web3 adoption expands and cryptocurrency valuations remain volatile, organizations face urgent risks of direct financial theft, regulatory scrutiny, and supply-chain exploitation.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attacks exposed inadequate segmentation, insufficient monitoring of east-west traffic, and gaps in anomaly detection and credential management within blockchain and crypto infrastructure.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Comprehensive zero trust segmentation, enforcement of least privilege network and identity policies, encrypted traffic controls, and egress filtering would have critically constrained BlueNoroff's ability to pivot internally, establish covert C2, and exfiltrate assets, reducing the blast radius and enabling earlier detection or prevention.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Restricts attack surface by enforcing inbound policy at the cloud perimeter.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Prevents privilege escalation through enforced least-privilege and microsegmentation.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Blocks unauthorized intra-cloud traffic and detects abnormal service-to-service connections.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Detects and blocks C2 traffic using signature-based and anomaly detection.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevents unauthorized data egress and enforces outbound policies.

Impact (Mitigations)

Early detection and containment of abnormal behaviors minimizes operational and financial losses.

Impact at a Glance

Affected Business Functions

  • Financial Transactions
  • Client Communications
  • Software Development
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Potential exposure of sensitive financial data, client information, and intellectual property related to blockchain and cryptocurrency operations.

Recommended Actions

  • Enforce zero trust segmentation across all cloud workloads, with identity-based microsegmentation policies to eliminate lateral movement paths.
  • Deploy comprehensive east-west and egress traffic security, including deep packet inspection and application-aware filtering, across multi-cloud networks.
  • Integrate cloud-native firewalls and inline IPS to block known exploits, command and control techniques, and prevent exposure of critical assets.
  • Implement centralized, real-time threat detection and anomaly response to rapidly contain suspicious activity and pre-empt data exfiltration attempts.
  • Continuously audit and enforce least-privilege IAM roles and network policies to reduce the risk of privilege escalation and unauthorized cloud access.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image