North Korean BlueNoroff Uses Deepfakes in Zoom Scams to Install macOS Malware for Crypto Theft

Huntress uncovered a complex cyberattack by North Korean threat actor TA444, involving a fake Zoom extension, AppleScript abuse, and a custom macOS malware suite to steal cryptocurrency. The attack used social engineering, deepfake impersonations, and sophisticated macOS techniques, targeting organizations in the crypto and fintech sectors. #TA444 #BlueNoroff #macOSmalware #cryptosecurity…

Read More
Zooming through BlueNoroff Indicators with Validin

The article analyzes a targeted intrusion by the North Korean BlueNoroff threat group against a Web3 organization, focusing on phishing lures disguised as Zoom extensions and extensive infrastructure pivoting using DNS, host, and registration data. Nearly 200 related malicious domains and numerous IP addresses linked to DPRK activity were identified to enable proactive threat tracking. #BlueNoroff #APT38 #LazarusGroup #ZoomExtension #Validin

Read More
BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware

North Korean threat actor BlueNoroff has been exploiting remote workers in the Web3 sector through sophisticated deepfake Zoom calls to deliver malware onto macOS devices. The group is known for targeting cryptocurrency organizations and evolving its attack methods with multi-stage payloads. #BlueNoroff #APT38 #CryptoTraitor #GolamagGhost #TraderTraitor…

Read More
North Korea targeting Indian crypto job applicants with malware

North Korean hackers, specifically the group “Famous Chollima,” are targeting job applicants in the cryptocurrency and blockchain sector to infect devices and steal data. Their campaigns involve fake employer websites, skill tests, and malware like PylangGhost and INLETDRIFT to manipulate victims into unwittingly installing malicious software. #NorthKoreanHackers #FamousChollima #CryptocurrencyTheft #Malware #CyberEspionage…

Read More
Organizations Warned of Vulnerability Exploited Against Discontinued TP-Link Routers

Threat actors are actively exploiting a two-year-old security vulnerability in discontinued TP-Link routers, specifically models like TL-WR940N, TL-WR841N, and TL-WR740N. CISA has warned users to cease using these outdated devices and has added the CVE-2023-33538 vulnerability to its KEV list due to active exploitation. #CISA #TPLinkVulnerability…

Read More
Cybersecurity News | Daily Recap [16 Jun 2025]

Dark Web law enforcement actions succeeded in dismantling the Archetyp Market, a significant darknet drug hub, leading to arrests and €7.8 million in seized assets. Additionally, notable data breaches impacted Zoomcar and Asheville Eye Associates, while evolving ransomware and malware like Anubis and Predator spyware continue to pose threats. These incidents highlight ongoing challenges in cybersecurity, emphasizing the need for vigilant protection and strategic defenses. #ArchetypMarket #AnubisRansomware #PredatorSpyware #ZoomcarDataBreach #AshevilleEyeBreach

Read More

Cybersecurity researchers have identified malicious packages on PyPI and npm that target developers by stealing sensitive data, including credentials and environment variables. These threats demonstrate sophisticated multi-stage attack methods and emphasize the importance of vigilant security practices in open-source development environments. #chimera-sandbox-extensions #Pypi #npm #PulsarRAT #slopsquatting…

Read More
Danish government agency to ditch Microsoft software in push for digital independence

Denmark’s government agencies are transitioning from Microsoft products to open-source software like LibreOffice to enhance digital sovereignty and reduce reliance on U.S. tech companies. The move is driven by cost, market dominance concerns, and geopolitical tensions, aligning with a broader European trend toward digital independence. #LibreOffice #DigitalSovereignty…

Read More
Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider

Ransomware actors have been exploiting a path traversal vulnerability (CVE-2024-57727) in SimpleHelp Remote Monitoring and Management (RMM) version 5.5.7 and earlier to target downstream customers, particularly in the utility billing sector. CISA urges immediate mitigation steps including software upgrades, system isolation, and threat hunting to prevent and respond to these attacks….

Read More