Tektronix TIF 2026
This page was machine-translated and may differ from the original. View original

Kaspersky Warns of North Korean Virtual Asset Theft Campaign

Google 우선 소스Published2026.04.16 11:51

Targeting Web3 with Fake Video Conferencing and Recruitment Bait

Bluenoroff, identified as a North Korea-linked hacking group, appears to have evolved its methods of stealing virtual assets to be even more sophisticated. Analysis suggests that the scope of attacks is expanding beyond simply targeting cryptocurrency wallets to simultaneously taking control of video conferencing, recruitment processes, cloud accounts, messengers, and browser credentials.

On the 16th, global security firm Kaspersky released an in-depth report containing these details and urged Web3 and blockchain industry professionals to exercise special caution.

The key to this analysis is the two-pronged attack known as 'GhostCall' and 'GhostHire'.

According to data released by Kaspersky, BlueNoroff has been tracked since at least April 2025, and the targets of the attacks have narrowed down to blockchain developers, venture capitalists, and startup executives.

A common tactic involves approaching victims via Telegram, posing as investors or recruiters, and inducing them to execute malware after gaining their trust.

Ghost Call is an attack that uses a video conference as bait.

Victims are lured to fake Zoom or Teams pages disguised as investment discussions or partnership meetings.

In this process, the attacker plays a video of the victim's actual past meeting instead of a deepfake to make it look like a 'real meeting currently connected.'

Subsequently, it induces the installation of fake updates under the pretext of resolving audio issues or program errors, and if the user executes them, a chain of infection begins.

In particular, Kaspersky explained that this campaign was primarily aimed at the macOS environment.

Ghost Hire is an infiltration method disguised as a recruitment process.

Attackers impersonate recruiters from U.S. financial companies or global corporations to approach Web3 developers and demand that they perform technical evaluation tasks.
The victim receives a compressed file or repository via a Telegram bot or GitHub link, usually accompanied by time pressure such as “submit within 30 minutes.”

The short time limit robs you of time for verification and acts as a psychological tactic that ultimately forces the malicious project to be executed as is.

The report pointed out that this attack is not simple phishing but is carried out through a multi-stage malware chain.

Kaspersky announced that it has identified at least seven infection streams and several new malicious components.

This includes features such as browser credential theft, Telegram account collection, cryptocurrency wallet information leakage, and the collection of various private keys and API keys.

The released data also contains evidence that the attacker targeted OpenAI-related directories in an attempt to secure traces of ChatGPT account usage.

What stands out particularly is the use of generative AI.

Kaspersky stated that it detected evidence that BlueNoroff used AI tools in various stages of the attack, including creating fake profile images, writing malicious scripts, and refining code.

Analysis suggests that this can act as a factor that shortens attack preparation time and accelerates the adoption of new programming languages and obfuscation techniques.

Kaspersky stated that victims have been confirmed in various regions, including Japan, Italy, France, Singapore, India, and Hong Kong.

In particular, tech company executives, venture capitalists, and developers working in the Web3 and blockchain industries were the primary targets.

The company emphasized that one should be wary of sudden investment offers or recruitment contacts via Telegram, as well as requests for code tests that rush execution.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
배종인 기자
배종인 기자