Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • DeFi
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • Gaming
  • Legal
    • Taxes & Regulation
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Converter
What's Hot

Here’s why Aerodrome Finance’s AERO token price is soaring

June 15, 2025

Donald Trump Warns Fed: Slash Rates or I’ll “Force Something” – Powell’s Job Still Safe

June 15, 2025

Lido’s Ethereum staking share drops 9% in 2025 – Can LDO flip 75% losses? 

June 15, 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Buy Crypto NewsBuy Crypto News
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    $1.14 Billion Wiped Out as Market Faces Double Attack? 

    June 15, 2025

    Here Are the Possible Bearish Targets for Bitcoin After BTC Fails To Break Out Above Major Level, According to Crypto Analyst

    June 14, 2025

    Bitcoin Bounces to $106K After Iran-Israel Jitters, but Analysts Warn of Deeper Pullback

    June 14, 2025

    The 30,000-Foot View Of The Oslo Freedom Forum

    June 14, 2025

    Lido’s Ethereum staking share drops 9% in 2025 – Can LDO flip 75% losses? 

    June 15, 2025

    What’s making Ethereum more attractive than Bitcoin right now

    June 14, 2025

    Mapping Bitcoin, Ethereum’s moves amid Middle Eastern tensions, tariff wars

    June 14, 2025

    Ethereum: Smart money buys the dip as ETH dives 9% – What’s next?

    June 14, 2025

    Mapping Optimism’s future: Major breakout or a pullback?

    June 14, 2025

    Billionaire Snaps Up $100M Of Trump Coin After Investigation Ends

    June 14, 2025

    Bitcoin ETF inflows explode $970 mln: Will BTC ride this wave to more gains?

    June 14, 2025

    Several Fund Managers Files Updated Form S-1 With U.S. SEC

    June 14, 2025

    Pepe, BMT, CAKE: Crypto Activity Heats Up

    March 18, 2025

    SHIB Burns Over Half a Billion Tokens, Price Surges Over 7%

    March 17, 2025

    DOGE Sees Massive User Growth: Active Addresses Up 400%

    March 15, 2025

    Shiba Inu (SHIB) Price Analysis: Bullish Hints, Bearish Trend

    March 15, 2025

    Here’s why Aerodrome Finance’s AERO token price is soaring

    June 15, 2025

    Donald Trump Warns Fed: Slash Rates or I’ll “Force Something” – Powell’s Job Still Safe

    June 15, 2025

    Lido’s Ethereum staking share drops 9% in 2025 – Can LDO flip 75% losses? 

    June 15, 2025

    $1.14 Billion Wiped Out as Market Faces Double Attack? 

    June 15, 2025
  • DeFi

    Here’s why Aerodrome Finance’s AERO token price is soaring

    June 15, 2025

    Sonic poised for deeper correction ahead despite a potential Coinbase listing

    June 14, 2025

    HYPE steadies after sharp pullback from ATH amid market tumble

    June 14, 2025

    Ethereum Foundation Stakes $1.25M War Chest to Shield Tornado Cash’s Roman Storm

    June 14, 2025

    Cardano’s $100M plan to tackle DeFi and stablecoin challenges

    June 14, 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Donald Trump Warns Fed: Slash Rates or I’ll “Force Something” – Powell’s Job Still Safe

    June 15, 2025

    The Real Lifestyle Teams Up with Bitsolara for Gamified Web3 Transport Innovation

    June 14, 2025

    Stablecoin Surge: Market Cap Hits Record $228B in 2025 Amid Trading Boom and Trump-Era Clarity

    June 14, 2025

    Startup DIMO Launches DePIN Venture in Japan to Help Automakers Monetize Vehicle Data

    June 14, 2025

    Coinbase data breach spills offline as victims get scam mail

    June 6, 2025

    Cryptojacking Campaign Targets DevOps Servers Including Nomad

    June 3, 2025

    Sophisticated Malware Campaign Targets Windows and Linux Systems

    June 2, 2025

    US Treasury sanctions Philippines tech firm over aiding $200 million pig butchering spree

    May 31, 2025

    Here’s why Aerodrome Finance’s AERO token price is soaring

    June 15, 2025

    Donald Trump Warns Fed: Slash Rates or I’ll “Force Something” – Powell’s Job Still Safe

    June 15, 2025

    Lido’s Ethereum staking share drops 9% in 2025 – Can LDO flip 75% losses? 

    June 15, 2025

    $1.14 Billion Wiped Out as Market Faces Double Attack? 

    June 15, 2025
  • Web 3
    1. Web3 News
    2. Gaming
    3. View All

    Ripplecoin Mining Free Cloud Mining App, High-yield Cloud Mining Investment Guide for BTC and XRP Holders

    June 14, 2025

    Digital Forensics Market 2025-2033: Key Players Include Cellebrite, Magnet Forensics, and AccessData

    June 14, 2025

    Sunny Mining achieves breakthrough AI-driven technology,Becoming a profitable milestone in the cloud mining industry

    June 14, 2025

    Wondershare Announces Breakthrough Solution for Recovering Data from Android Devices with Broken Screens

    June 14, 2025

    Why are big games building on Avalanche instead of Ethereum?

    June 14, 2025

    NFT – what is it and why is it needed?

    June 13, 2025

    ‘FIFA Rivals’ Launches—Why Mythical Games Thinks It’ll Hit Bigger Than ‘NFL Rivals’

    June 13, 2025

    Off The Grid active wallets hold steady ahead of Steam launch

    June 13, 2025

    Here’s why Aerodrome Finance’s AERO token price is soaring

    June 15, 2025

    Donald Trump Warns Fed: Slash Rates or I’ll “Force Something” – Powell’s Job Still Safe

    June 15, 2025

    Lido’s Ethereum staking share drops 9% in 2025 – Can LDO flip 75% losses? 

    June 15, 2025

    $1.14 Billion Wiped Out as Market Faces Double Attack? 

    June 15, 2025
  • Legal
    1. Taxes & Regulation
    2. Adoption
    3. View All

    Cynthia Lummis Proposes Artificial Intelligence Bill, Requiring AI Firms to Disclose Technicals

    June 14, 2025

    Ethereum Foundation pledges $1M to Storm’s defense, entities boost Pertsev appeal

    June 14, 2025

    Latest Motion Could Make or Break It

    June 14, 2025

    Liquid Staking: The Most Complete Guide on the Internet

    June 14, 2025

    XRP’s corporate treasury investments near $1 billion

    June 14, 2025

    SharpLink leads with $463M Ethereum treasury move

    June 14, 2025

    Anthony Pompliano planning $750 million Bitcoin-focused investment firm via SPAC

    June 14, 2025

    Invesco and Galaxy trust hints at US Solana ETF ambitions

    June 14, 2025

    Here’s why Aerodrome Finance’s AERO token price is soaring

    June 15, 2025

    Donald Trump Warns Fed: Slash Rates or I’ll “Force Something” – Powell’s Job Still Safe

    June 15, 2025

    Lido’s Ethereum staking share drops 9% in 2025 – Can LDO flip 75% losses? 

    June 15, 2025

    $1.14 Billion Wiped Out as Market Faces Double Attack? 

    June 15, 2025
  • Analysis

    This Dogecoin Rival Could Go Higher Amid Increased Whale Activity, Says Analytics Platform Santiment

    June 14, 2025

    Bitcoin (BTC) Price Drop To $105k Divides Crypto Traders: What Next?

    June 14, 2025

    Polkadot seeks stability with $2M Bitcoin reserve strategy amid DOT downturn

    June 13, 2025

    Is the Capital Rotation Already Underway?

    June 13, 2025

    Leading Stablecoin Issuer Tether Invests $89,000,000 Into Precious Metals Royalty Company To Deepen Exposure to Gold

    June 13, 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What is a Corporate Bitcoin Treasury? The Strategy Behind Companies Holding Crypto

    May 27, 2025

    What Are Tokenized Real-World Assets? Putting Physical Value On-Chain With RWAs

    May 19, 2025

    Users Taunt Grok After xAI Says Modifications Were Made to Spit out ‘White Genocide’ Claim

    May 16, 2025

    What Is Base? The Ethereum Layer-2 Network Launched by Coinbase

    April 29, 2025

    Every crypto trade will soon happen inside your wallet

    June 14, 2025

    Coinbase to launch CFTC-cleared perpetual futures trading, Bitcoin-backed credit card for US customers

    June 13, 2025

    FTX continues to exclude Nigeria and China in remaining creditor repayments but includes Payoneer

    June 12, 2025

    BiT Global drops Coinbase lawsuit over wrapped Bitcoin delisting

    June 10, 2025

    Here’s why Aerodrome Finance’s AERO token price is soaring

    June 15, 2025

    Donald Trump Warns Fed: Slash Rates or I’ll “Force Something” – Powell’s Job Still Safe

    June 15, 2025

    Lido’s Ethereum staking share drops 9% in 2025 – Can LDO flip 75% losses? 

    June 15, 2025

    $1.14 Billion Wiped Out as Market Faces Double Attack? 

    June 15, 2025
  • Tools
    • Market Overview
    • Converter
Buy Crypto NewsBuy Crypto News
Home»Security and Privacy»North Korean Actor Deploys Novel Malware Campaign Against Crypto Firms
Security and Privacy

North Korean Actor Deploys Novel Malware Campaign Against Crypto Firms

November 24, 2024Updated:November 24, 2024No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A notorious threat actor with ties to North Korea is targeting cryptocurrency firms using a sophisticated multi-stage malware campaign, according to a recent report by SentinelLabs.

The campaign, known as ‘Hidden Risk’, is believed to be the work of the BlueNoroff advanced persistent threat (APT) group, which is notorious for financially motivated attacks. This particular campaign is aimed at macOS devices.

The attack begins with a phishing email, through which two types of malware are deployed upon initial infection. One notable aspect of this campaign is the use of a novel persistence mechanism in a backdoor malware that exploits the Zshenv configuration file.

Furthermore, the attackers have demonstrated their ability to hijack valid Apple ‘identified developer’ accounts at will, enabling them to bypass macOS Gatekeeper and other built-in Apple security measures.

Unlike previous North Korean attacks on crypto-related industries, which involved extensive social media targeting, the Hidden Risk campaign relies on a more traditional email phishing approach. Despite the simplicity of the initial infection method, the campaign still bears the hallmarks of previous DPRK-backed attacks in terms of malware artifacts and network infrastructure.

In light of this new campaign and the overall increase in macOS crimeware, SentinelLabs advises all macOS users to strengthen their security measures and be vigilant against potential risks.

The FBI has also issued a warning about cyber actors in North Korea using sophisticated social engineering tactics against cryptocurrency operations.

Multi-Stage Malware Campaign

The attack begins with a phishing email containing a link to a malicious application that initiates the infection process. The application is disguised as a link to a PDF document related to cryptocurrency topics, such as the “Hidden Risk Behind New Surge of Bitcoin Price.”

See also  Crypto-Exchange Offers $250K Reward for Info on Attackers

The phishing email appears to come from a real person in an unrelated industry, forwarding a message from a well-known crypto influencer. However, the email lacks personalized information related to the recipient.

Upon clicking the link in the email, the user is directed to a malicious domain, delphidigital[.]org, which serves the first stage of the malware application titled ‘Hidden Risk Behind New Surge of Bitcoin Price.app.’

This application is a Mac application written in Swift and signed with the Apple Developer ID “Avantis Regtech Private Limited (2S8XHJ7948).” The application downloads a decoy PDF file and executes a malicious binary that leads to the second stage of the malware.

The second stage malware acts as a backdoor, allowing remote command execution on the infected device.

Novel Persistence Technique

The backdoor malware used in this campaign employs a unique persistence mechanism by abusing the Zshenv configuration file, which is utilized by the Zsh shell on macOS.

By infecting the host with a malicious Zshenv file, the attackers ensure persistent access to the system across all Zsh sessions, including interactive and non-interactive shells, non-login shells, and scripts.

This technique is particularly effective on modern versions of macOS, as it bypasses user notifications that typically warn users of persistence methods being installed.

The campaign has been attributed to the BlueNoroff group based on analysis of the network infrastructure controlled and operated by the threat actor.

In conclusion, the Hidden Risk campaign underscores the importance of robust security measures for macOS users, as cyber threats continue to evolve and target cryptocurrency firms. Stay vigilant and implement necessary safeguards to protect against such sophisticated attacks.

See also  XRP and Cardano Gain Momentum While a Breakout New Crypto Captivates the Market
Actor Campaign Crypto deploys firms Korean Malware North
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Cynthia Lummis Proposes Artificial Intelligence Bill, Requiring AI Firms to Disclose Technicals

June 14, 2025

Here Are the Possible Bearish Targets for Bitcoin After BTC Fails To Break Out Above Major Level, According to Crypto Analyst

June 14, 2025

Proof of Talk 2025: RWAs, Stablecoins and Crypto IPOs Demonstrate Sector Growth

June 14, 2025

India cracks down on crypto tax evasion in enforcement push

June 14, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Bitcoin and Crypto About To Be Boosted by Global Money Supply Explosion: Former Goldman Sachs Executive

March 12, 2025

Revolutionizing Security in the Aptos Ecosystem

December 2, 2024

Telecommunication Relay Services Market: A Compelling Long-Term Growth Story

December 26, 2024
Price Chart


Explore insights on crypto, blockchain, taxes, and security. Stay informed with expert guides, tips, and the latest trends to navigate the digital asset world confidently


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Here’s why Aerodrome Finance’s AERO token price is soaring

June 15, 2025

Donald Trump Warns Fed: Slash Rates or I’ll “Force Something” – Powell’s Job Still Safe

June 15, 2025

Lido’s Ethereum staking share drops 9% in 2025 – Can LDO flip 75% losses? 

June 15, 2025
Get Informed

Subscribe to Updates

Get the latest creative news From BuyCryptoNews directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 BuyCryptoNews - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.