Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • DeFi
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • Gaming
  • Legal
    • Taxes & Regulation
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Converter
What's Hot

Curve Finance moves to new domain after DNS attack exposes security risks

May 14, 2025

South Korean Crypto Exchange Deregulation Plans Set to Rock Banking Sector

May 14, 2025

Crypto Trader Says Bitcoin on Cusp of Price Discovery Phase, Sees Ethereum Attacking December Highs

May 14, 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Buy Crypto NewsBuy Crypto News
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Jack Mallers’ Twenty One Capital And Tether Bought 4,812 Bitcoin For $458,700,000

    May 14, 2025

    Is Cardano Heading for a ‘Golden Cross’? If Yes, How High Can the ADA Price Go in 2025?

    May 14, 2025

    $1,100 Ethereum Could Be Coming Before Real Rally Kicks Off, According to Benjamin Cowen – Here’s Why

    May 13, 2025

    Animoca Brands Plans U.S. Listing to Capture ‘Unique Moment’ of Trump Administration: FT

    May 13, 2025

    Crypto Trader Says Bitcoin on Cusp of Price Discovery Phase, Sees Ethereum Attacking December Highs

    May 14, 2025

    Is Ethereum Dead And Gone? 

    May 14, 2025

    Ethereum Stakers Enter Profit Zone as Price Climbs Above $2,400

    May 13, 2025

    Ethereum stakers are back in profit! – Will this fuel ETH’s rally?

    May 13, 2025

    Dogecoin (DOGE) ready for another rally? Whale activity soars

    May 14, 2025

    What’s Next for XRP Price?

    May 14, 2025

    Crypto ETFs Set Record With $62,900,000,000 Yearly Flows After Four Straight Green Weeks: CoinShares

    May 13, 2025

    Cardano: As whale accumulation rises, will ADA see a potential surge?

    May 13, 2025

    Pepe, BMT, CAKE: Crypto Activity Heats Up

    March 18, 2025

    SHIB Burns Over Half a Billion Tokens, Price Surges Over 7%

    March 17, 2025

    DOGE Sees Massive User Growth: Active Addresses Up 400%

    March 15, 2025

    Shiba Inu (SHIB) Price Analysis: Bullish Hints, Bearish Trend

    March 15, 2025

    Curve Finance moves to new domain after DNS attack exposes security risks

    May 14, 2025

    South Korean Crypto Exchange Deregulation Plans Set to Rock Banking Sector

    May 14, 2025

    Crypto Trader Says Bitcoin on Cusp of Price Discovery Phase, Sees Ethereum Attacking December Highs

    May 14, 2025

    Jack Mallers’ Twenty One Capital And Tether Bought 4,812 Bitcoin For $458,700,000

    May 14, 2025
  • DeFi

    Curve Finance moves to new domain after DNS attack exposes security risks

    May 14, 2025

    Curve Finance battles DNS hijack days after X account breach

    May 14, 2025

    LAUNCHCOIN leads crypto market with 500% rally, what is Launch Coin on Believe?

    May 13, 2025

    ZKsync X accounts hacked to promote fake SEC warnings and malicious airdrop

    May 13, 2025

    Spot Bitcoin ETFs see three-week inflow streak totalling $5.8 billion

    May 13, 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    South Korean Crypto Exchange Deregulation Plans Set to Rock Banking Sector

    May 14, 2025

    B2 Network and Plume Network Bridge Bitcoin and RWAs

    May 14, 2025

    Tether’s $770M Gold-Backed Token XAU₮ Debuts On Thai Exchange Maxbit

    May 14, 2025

    EMC Protocol Joins daGama to Restore Trust in Real-World Ratings

    May 14, 2025

    FreeDrain Phishing Scam Drains Crypto Hobbyists’ Wallets

    May 12, 2025

    German Police Shutter “eXch” Money Laundering Service

    May 12, 2025

    Inferno Drainer Returns, Stealing Millions from Crypto Wallets

    May 8, 2025

    ZachXBT reveals Coinbase users lost another $45M in a week to ongoing social engineering scams

    May 8, 2025

    Curve Finance moves to new domain after DNS attack exposes security risks

    May 14, 2025

    South Korean Crypto Exchange Deregulation Plans Set to Rock Banking Sector

    May 14, 2025

    Crypto Trader Says Bitcoin on Cusp of Price Discovery Phase, Sees Ethereum Attacking December Highs

    May 14, 2025

    Jack Mallers’ Twenty One Capital And Tether Bought 4,812 Bitcoin For $458,700,000

    May 14, 2025
  • Web 3
    1. Web3 News
    2. Gaming
    3. View All

    .888: The Domain for Ambition and Prosperity

    May 14, 2025

    Folding Mountain Bike Market is Booming Worldwide |Schwinn,Xspec,Eurobike

    May 14, 2025

    Understanding DNS, Onchain + Web3 Domains

    May 13, 2025

    DVDFab Expands into E-Book Solutions with BookFab Kindle Converter

    May 13, 2025

    Legion IDO Launch: Get Ready for the Next Big Move in GameFi

    May 14, 2025

    Slither.io Solana Clone Goes Viral

    May 14, 2025

    Pudgy Penguins Launches’ Pengu Clash’—A Telegram-Based Web3 Game

    May 13, 2025

    5 of the Best Polkadot Games You Can Play Right Now

    May 13, 2025

    Curve Finance moves to new domain after DNS attack exposes security risks

    May 14, 2025

    South Korean Crypto Exchange Deregulation Plans Set to Rock Banking Sector

    May 14, 2025

    Crypto Trader Says Bitcoin on Cusp of Price Discovery Phase, Sees Ethereum Attacking December Highs

    May 14, 2025

    Jack Mallers’ Twenty One Capital And Tether Bought 4,812 Bitcoin For $458,700,000

    May 14, 2025
  • Legal
    1. Taxes & Regulation
    2. Adoption
    3. View All

    US lawmakers warn Treasury on taxing US firms’ unrealized crypto gains

    May 14, 2025

    Here’s the Latest Version – Provisions Affecting Tether Have Been Added

    May 14, 2025

    Fed council warns stablecoins may pose risk to bank deposits and credit capacity

    May 14, 2025

    Ripple’s Top Executive Stresses Ripple’s Tireless Fight Against Gensler’s SEC

    May 14, 2025

    Twenty One Capital becomes top Bitcoin holder with $458.7M purchase ahead of public listing

    May 14, 2025

    Coinbase makes history with S&P 500 induction, reinforcing crypto’s arrival in mainstream finance

    May 13, 2025

    Strategy and Metaplanet purchase combined 15,000 BTC for nearly $1.5 billion as Bitcoin rallies

    May 12, 2025

    Bitcoin yield without the leap of faith

    May 11, 2025

    Curve Finance moves to new domain after DNS attack exposes security risks

    May 14, 2025

    South Korean Crypto Exchange Deregulation Plans Set to Rock Banking Sector

    May 14, 2025

    Crypto Trader Says Bitcoin on Cusp of Price Discovery Phase, Sees Ethereum Attacking December Highs

    May 14, 2025

    Jack Mallers’ Twenty One Capital And Tether Bought 4,812 Bitcoin For $458,700,000

    May 14, 2025
  • Analysis

    Cardano Price Prediction 2026: Can ADA Hit $6 or $12?

    May 14, 2025

    Crypto liquidity lags behind traditional finance despite market efficiency gains – S&P Global

    May 14, 2025

    Will UNI Hit $8 Next?

    May 13, 2025

    Coinbase Head of Institutional Strategy Says Scarcity Driving Overwhelming Wave of Demand From Large Players

    May 13, 2025

    XRP outperforms crypto market with 10% jump as open interest surges past $5B

    May 12, 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is Base? The Ethereum Layer-2 Network Launched by Coinbase

    April 29, 2025

    What Is ‘Idle Mine’? This Free iOS and Android Game Pays Real Bitcoin

    April 20, 2025

    US Crypto Taxes in 2025: What You Need to Know

    April 4, 2025

    What Is Uniswap? Beginner’s Guide to the Leading Ethereum DEX

    April 3, 2025

    Brave Wallet expands support with Cardano integration

    May 13, 2025

    FTX EU victims can now withdraw trapped Euros via Backpack but crypto withdrawals remain blocked

    May 12, 2025

    Democrat Senators urge Treasury, DOJ to probe Trump’s crypto ties to Binance

    May 10, 2025

    Gemini secures license to expand EU crypto derivatives offerings

    May 9, 2025

    Curve Finance moves to new domain after DNS attack exposes security risks

    May 14, 2025

    South Korean Crypto Exchange Deregulation Plans Set to Rock Banking Sector

    May 14, 2025

    Crypto Trader Says Bitcoin on Cusp of Price Discovery Phase, Sees Ethereum Attacking December Highs

    May 14, 2025

    Jack Mallers’ Twenty One Capital And Tether Bought 4,812 Bitcoin For $458,700,000

    May 14, 2025
  • Tools
    • Market Overview
    • Converter
Buy Crypto NewsBuy Crypto News
Home»Security and Privacy»North Korean Actor Deploys Novel Malware Campaign Against Crypto Firms
Security and Privacy

North Korean Actor Deploys Novel Malware Campaign Against Crypto Firms

November 24, 2024Updated:November 24, 2024No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A notorious threat actor with ties to North Korea is targeting cryptocurrency firms using a sophisticated multi-stage malware campaign, according to a recent report by SentinelLabs.

The campaign, known as ‘Hidden Risk’, is believed to be the work of the BlueNoroff advanced persistent threat (APT) group, which is notorious for financially motivated attacks. This particular campaign is aimed at macOS devices.

The attack begins with a phishing email, through which two types of malware are deployed upon initial infection. One notable aspect of this campaign is the use of a novel persistence mechanism in a backdoor malware that exploits the Zshenv configuration file.

Furthermore, the attackers have demonstrated their ability to hijack valid Apple ‘identified developer’ accounts at will, enabling them to bypass macOS Gatekeeper and other built-in Apple security measures.

Unlike previous North Korean attacks on crypto-related industries, which involved extensive social media targeting, the Hidden Risk campaign relies on a more traditional email phishing approach. Despite the simplicity of the initial infection method, the campaign still bears the hallmarks of previous DPRK-backed attacks in terms of malware artifacts and network infrastructure.

In light of this new campaign and the overall increase in macOS crimeware, SentinelLabs advises all macOS users to strengthen their security measures and be vigilant against potential risks.

The FBI has also issued a warning about cyber actors in North Korea using sophisticated social engineering tactics against cryptocurrency operations.

Multi-Stage Malware Campaign

The attack begins with a phishing email containing a link to a malicious application that initiates the infection process. The application is disguised as a link to a PDF document related to cryptocurrency topics, such as the “Hidden Risk Behind New Surge of Bitcoin Price.”

See also  Euro Cops Bust $47m Money Laundering Operation

The phishing email appears to come from a real person in an unrelated industry, forwarding a message from a well-known crypto influencer. However, the email lacks personalized information related to the recipient.

Upon clicking the link in the email, the user is directed to a malicious domain, delphidigital[.]org, which serves the first stage of the malware application titled ‘Hidden Risk Behind New Surge of Bitcoin Price.app.’

This application is a Mac application written in Swift and signed with the Apple Developer ID “Avantis Regtech Private Limited (2S8XHJ7948).” The application downloads a decoy PDF file and executes a malicious binary that leads to the second stage of the malware.

The second stage malware acts as a backdoor, allowing remote command execution on the infected device.

Novel Persistence Technique

The backdoor malware used in this campaign employs a unique persistence mechanism by abusing the Zshenv configuration file, which is utilized by the Zsh shell on macOS.

By infecting the host with a malicious Zshenv file, the attackers ensure persistent access to the system across all Zsh sessions, including interactive and non-interactive shells, non-login shells, and scripts.

This technique is particularly effective on modern versions of macOS, as it bypasses user notifications that typically warn users of persistence methods being installed.

The campaign has been attributed to the BlueNoroff group based on analysis of the network infrastructure controlled and operated by the threat actor.

In conclusion, the Hidden Risk campaign underscores the importance of robust security measures for macOS users, as cyber threats continue to evolve and target cryptocurrency firms. Stay vigilant and implement necessary safeguards to protect against such sophisticated attacks.

See also  Hack of Japanese Crypto Exchange DMM Pinned on North Korea
Actor Campaign Crypto deploys firms Korean Malware North
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

South Korean Crypto Exchange Deregulation Plans Set to Rock Banking Sector

May 14, 2025

Crypto Trader Says Bitcoin on Cusp of Price Discovery Phase, Sees Ethereum Attacking December Highs

May 14, 2025

US lawmakers warn Treasury on taxing US firms’ unrealized crypto gains

May 14, 2025

Crypto liquidity lags behind traditional finance despite market efficiency gains – S&P Global

May 14, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Telecom Outsourcing Market Innovations and Key Players: Cisco Systems, NEC Corporation, Huawei Technologies, Motorola Solutions, Nokia Networks, Ericsson, ZTE Corporation, Fujitsu Limited

February 3, 2025

Productivity Software Publishing Global Market Report 2025: Exponential Growth and Key Trends

February 1, 2025

Solana & Ethereum Lose Nearly 50% of Day’s Gains—Is There Something to Worry About?

March 4, 2025
Price Chart


Explore insights on crypto, blockchain, taxes, and security. Stay informed with expert guides, tips, and the latest trends to navigate the digital asset world confidently


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Curve Finance moves to new domain after DNS attack exposes security risks

May 14, 2025

South Korean Crypto Exchange Deregulation Plans Set to Rock Banking Sector

May 14, 2025

Crypto Trader Says Bitcoin on Cusp of Price Discovery Phase, Sees Ethereum Attacking December Highs

May 14, 2025
Get Informed

Subscribe to Updates

Get the latest creative news From BuyCryptoNews directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 BuyCryptoNews - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.