Vietnam.vn - Nền tảng quảng bá Việt Nam

Investment scams so sophisticated that anyone can fall into the trap

(NLDO) - Just follow the scammer's instructions, the device will automatically download malware and activate spyware, stealing people's information.

Người Lao ĐộngNgười Lao Động09/12/2025

Kaspersky's Global Research and Analysis Team (GReAT) has just announced the latest activity of the APT hacker group BlueNoroff - a branch of the notorious Lazarus cybercrime group, through two sophisticated targeted attack campaigns GhostCall and GhostHire.

These campaigns targeted Web3 and cryptocurrency organizations in India, Türkiye, Australia, and several countries in Europe and Asia, and have been ongoing since at least April 2025.

The GhostCall and GhostHire campaigns are said to use new intrusion techniques and custom-designed malware, aiming to infiltrate developer systems and attack blockchain organizations and businesses for financial gain.

These attacks primarily targeted macOS and Windows operating systems and were coordinated through a unified command-and-control infrastructure.

The GhostCall campaign focuses on macOS devices. Attackers approach victims via Telegram, impersonating venture capitalists, and even use compromised accounts of real entrepreneurs and startup founders to propose investment or partnership opportunities.

Chiêu lừa đầu tư mới tinh vi tới mức ai cũng có thể sập bẫy - Ảnh 1.

GhostCall Campaign Attack Methodology

Victims are then invited to an “investment meeting” on scam pages that mimic the Zoom or Microsoft Teams interface.

During this fake meeting, the victim will be asked to update the app to fix the audio issue. Once done, the device will download a piece of malicious code and deploy spyware onto the device.

In the GhostHire campaign, this advanced persistent threat (APT) group targeted blockchain developers by impersonating recruiters. Victims were tricked into downloading and running a malicious GitHub repository disguised as a skills test.

Chiêu lừa đầu tư mới tinh vi tới mức ai cũng có thể sập bẫy - Ảnh 2.

How the GhostHire campaign was attacked

When the victim opens and runs the content, the malware installs itself on the machine, customized to suit the victim's operating system.

Kaspersky recommends being cautious with attractive offers or investment proposals. Always verify the identity of any new contacts, especially if they reach out via Telegram, LinkedIn or other social media platforms.

Be sure to only use authenticated and secure internal communication channels for communications containing sensitive information, always consider the possibility that an acquaintance's account has been compromised, and avoid running unverified scripts or commands just to "fix a bug"...

Source: https://nld.com.vn/chieu-lua-dau-tu-tinh-vi-den-muc-ai-cung-co-the-sap-bay-196251209162029124.htm


Comment (0)

Please leave a comment to share your feelings!

Same tag

Same category

What's in the 100m alley that's causing a stir at Christmas?
Overwhelmed by the super wedding held for 7 days and nights in Phu Quoc
Ancient Costume Parade: A Hundred Flowers Joy
Bui Cong Nam and Lam Bao Ngoc compete in high-pitched voices

Same author

Heritage

Figure

Enterprise

People's Artist Xuan Bac was the "master of ceremonies" for 80 couples getting married together on Hoan Kiem Lake walking street.

News

Political System

Destination

Product

Footer Banner Agribank
Footer Banner LPBank
Footer Banner MBBank
Footer Banner VNVC
Footer Banner Agribank
Footer Banner LPBank
Footer Banner MBBank
Footer Banner VNVC
Footer Banner Agribank
Footer Banner LPBank
Footer Banner MBBank
Footer Banner VNVC
Footer Banner Agribank
Footer Banner LPBank
Footer Banner MBBank
Footer Banner VNVC