The North Korean APT group BlueNoroff β also known as Sapphire Sleet, APT38, Alluring Pisces, Stardust Chollima, and TA444 β has launched two intertwined cyber-espionage and financial-theft campaigns under its long-running SnatchCrypto operation. According to a new report from Kaspersky, the campaigns, dubbed GhostCall and GhostHire, demonstrate the actorβs escalating sophistication, shifting fully to macOS and integrating AI-generated content to enhance social-engineering realism.
The GhostCall operation targets blockchain executives and venture-capital leaders by inviting them to join seemingly legitimate Zoom or Microsoft Teams meetings. Kaspersky explains that βthe GhostCall campaign is a sophisticated attack that uses fake online calls with the threat actors posing as fake entrepreneurs or investors to convince targets.β Once a victim joins, prerecorded videos of previous victims are played to create the illusion of a live discussion, while a fraudulent prompt urges the participant to βupdate the Zoom SDK.β
That βupdateβ is a malicious AppleScript that downloads further payloads. Kasperskyβs researchers describe how βthe actor reaches out to targets on Telegram by impersonating venture capitalists and, in some cases, using compromised accounts of real entrepreneurs and startup founders.β The fake sites replicate Zoomβs interface with near-pixel accuracy, including live camera and name prompts to maintain authenticity.

The campaign has gradually migrated from Zoom to Microsoft Teams, signaling adaptability to corporate trends and suggesting the attackersβ deep understanding of business collaboration tools.
Kasperskyβs analysis reveals an intricate web of multi-stage infection chains, each modularly constructed to evade detection. The firm identified at least seven distinct sequences β including DownTroy, CosmicDoor, RooTroy, SneakMain, and RealTimeTroy β along with a keylogger and a stealer suite named SilentSiphon.
The SilentSiphon suite is described as βa collection of Bash shell scripts used to collect and exfiltrate data to the actorβs C2 servers.β It targets credentials, API keys, cryptocurrency wallets, DevOps configurations, and even OpenAI API tokens, effectively granting the attackers potential access to both personal and enterprise infrastructure.
Notably, BlueNoroffβs engineers have transitioned from Rust to Nim, employing C++, Go, Swift, and Python to diversify their malware base. This βlanguage agilityβ complicates attribution and hampers antivirus detection, underscoring the groupβs resource depth.
While the GhostCall operation relies on prerecorded videos instead of deepfakes, Kaspersky uncovered that BlueNoroff enhances stolen or scraped profile images using GPT-4o. The report states, βSome of these images were enhanced with GPT-4o. Since OpenAI implemented the C2PA standard specification metadata to identify the generated images as artificial, the images created via ChatGPT include metadata that indicates their synthetic origin.β
This hybrid use of real footage and AI-polished visuals blurs authenticity lines, making the attacks nearly indistinguishable from legitimate investor interactions. The group also appears to employ AI-written code snippets within malware modules β a rare glimpse into automated offensive scripting. Kaspersky observed that βthe secrets stealer module includes several comment lines, one of them using a checkmark emoticon β suggesting BlueNoroff uses generative AI to write malicious scripts.β
The GhostHire campaign parallels GhostCallβs tactics but masquerades as recruitment outreach. Developers and engineers receive Telegram messages from βrecruitersβ posing as representatives of major fintech firms. Victims are sent a coding challenge via Telegram bot or GitHub repository and pressured to finish within 30 minutes β a psychological trick that boosts infection success.
The malicious Go project imports a fake dependency named uniroute, which decodes a base64-encoded URL and downloads OS-specific payloads. On macOS, these payloads again deploy DownTroy, connecting both campaigns into a cohesive ecosystem.
Kaspersky notes that βthe project delivered through the ZIP file appears to be a legitimate DeFi-related project written in Go, aiming at routing cryptocurrency transactions across various protocols,β but the hidden dependency injects the malware into the targetβs system.

Among the discovered chains, DownTroy stands out as the main downloader and persistence enabler. By abusing macOSβs Transparency, Consent, and Control (TCC) framework, it can silently grant automation and file-access permissions without user consent. Other modules like ZoomClutch mimic legitimate applications, prompt for system passwords, and exfiltrate them to C2 servers.
Kaspersky confirms that βZoomClutch steals macOS passwords by displaying a fake Zoom dialog, then sends the captured credentials to the C2 server.β
Once known for cryptocurrency theft, BlueNoroff now operates with the precision of an AI-driven cyber-espionage unit, merging social engineering, cross-platform development, and artificial intelligence.
Kaspersky concludes its analysis with a warning: βWe observed the actor utilizing AI in various aspects of their attacks, which enabled them to enhance productivity and meticulously refine their attacks.β
Related Posts:
- New Mirai Botnet Variants with AI-Powered Attacks Observed
- North Korea’s AI-Powered Cybercrime: Deepfakes & Fake Personas Infiltrate 300+ US Companies via Remote IT Jobs
- BlueNoroffβs New MacOS Threat: βHidden Riskβ Targets Crypto Enthusiasts
- Crypto-Targeting BlueNoroff APT Expands Arsenal with New macOS Malware
- Jamf Threat Labs Uncovers a Stealthy Malware Strain from BlueNoroff APT
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.