Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
What's Hot

FishWar Partners With RATGPT To Enhance Web3 Gaming Experience With Decentralized AI Network

June 6, 2026

A little-known 1,250% rule could lock US banks out of Bitcoin

June 6, 2026

Cardano social activity surges as ADA falls under 20 cents to four-year lows

June 6, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Cardano social activity surges as ADA falls under 20 cents to four-year lows

    June 6, 2026

    The Hyperinflation Of 1971 At The Kindergarten

    June 6, 2026

    Bitcoin DATs bleed amid BTC’s extended market slump: What’s next?

    June 6, 2026

    Is Bitcoin’s Bottom Near? Glassnode Co-Founder Reveals Key Price Zone

    June 6, 2026

    Ethereum Liquidation Risk Mounts as $547 Million in DeFi Positions Near Critical Levels

    June 5, 2026

    Bankless Founder Calls Ethereum a Failed Project

    June 5, 2026

    Bitmine Seeks $300M Raise To Accelerate Ethereum Accumulation Strategy

    June 5, 2026

    Tom Lee’s BitMine Seeks $300 Million Raise to Buy More Ethereum

    June 4, 2026

    Veteran Analyst Eyes $53,000 Bitcoin As Final Cycle Stage Begins

    June 6, 2026

    Bitcoin Critic Peter Schiff Predicts USDT Will Eclipse BTC

    June 6, 2026

    Here’s How High The Bitcoin Price Will Climb If It Breaks The Current Bear Trend

    June 5, 2026

    Bitcoin In Vulnerable Position As 2022 Setup Repeats –$54K Next?

    June 5, 2026

    Meme Coin Market Faces Imbalance as Supply Rises, Demand Falls

    April 4, 2026

    Crypto Interest Rising Toward Meme Coin Sector

    January 9, 2026

    Memes Market Cap Adds $10B in Days: Fresh Capital or Dead-Cat-Bounce?

    January 5, 2026

    Meme Coin Market Surges Past $45B as Shiba Inu, PEPE, BONK Stage 54% Price Pump

    January 4, 2026

    FishWar Partners With RATGPT To Enhance Web3 Gaming Experience With Decentralized AI Network

    June 6, 2026

    A little-known 1,250% rule could lock US banks out of Bitcoin

    June 6, 2026

    Cardano social activity surges as ADA falls under 20 cents to four-year lows

    June 6, 2026

    New Defend Developers PAC targets key races with DeFi on the line

    June 6, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    FishWar Partners With RATGPT To Enhance Web3 Gaming Experience With Decentralized AI Network

    June 6, 2026

    Why Circle Chose the Network for a Key Stablecoin Deployment

    June 6, 2026

    Tokenized gold platform Pleasing Market migrates $90M in TVL from LayerZero to Chainlink

    June 6, 2026

    Coinbase’s x402 has processed over 100 million transactions on Base

    June 6, 2026

    Infosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark Web

    June 3, 2026

    Stake DAO Freezes Arbitrum vsdCRV Markets After Attacker Mints 5.4T Synthetic Tokens

    May 29, 2026

    Certik Unveils ‘Anti-Virus for AI Agents’ as Skill Marketplaces Face Hidden Threats

    May 29, 2026

    New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

    May 28, 2026

    FishWar Partners With RATGPT To Enhance Web3 Gaming Experience With Decentralized AI Network

    June 6, 2026

    A little-known 1,250% rule could lock US banks out of Bitcoin

    June 6, 2026

    Cardano social activity surges as ADA falls under 20 cents to four-year lows

    June 6, 2026

    New Defend Developers PAC targets key races with DeFi on the line

    June 6, 2026
  • Web 3
    1. Gaming
    2. View All

    Binance NFT Marketplace Is Dead And Nobody Should Be Surprised

    June 5, 2026

    Pi Network Expands Gaming Ecosystem as CiDi Games Launches Developer Center

    June 3, 2026

    GMATRIXS Taps GamePad to Boost Web3 Gaming and DeFi Infrastructure

    June 3, 2026

    Code as Constitution: How Crypto Governance Is Moving Into the Real World

    June 2, 2026

    FishWar Partners With RATGPT To Enhance Web3 Gaming Experience With Decentralized AI Network

    June 6, 2026

    A little-known 1,250% rule could lock US banks out of Bitcoin

    June 6, 2026

    Cardano social activity surges as ADA falls under 20 cents to four-year lows

    June 6, 2026

    New Defend Developers PAC targets key races with DeFi on the line

    June 6, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    A little-known 1,250% rule could lock US banks out of Bitcoin

    June 6, 2026

    New Defend Developers PAC targets key races with DeFi on the line

    June 6, 2026

    Coinbase Employees Found Behind ‘Law Enforcement’ Letter to Congress

    June 6, 2026

    Stripe Millionaire Loses Bid for Congress to Candidate Backed by Ripple Co-Founder

    June 6, 2026

    Bank of England stablecoin caps may choke the UK’s pound-token market before launch

    June 3, 2026

    Cardano just canceled is 2026 Summit

    June 2, 2026

    Trader turns $2,480 into $12 million after holding Binance memecoin for 8 months

    June 1, 2026

    Crypto walked so banks could run

    May 30, 2026

    FishWar Partners With RATGPT To Enhance Web3 Gaming Experience With Decentralized AI Network

    June 6, 2026

    A little-known 1,250% rule could lock US banks out of Bitcoin

    June 6, 2026

    Cardano social activity surges as ADA falls under 20 cents to four-year lows

    June 6, 2026

    New Defend Developers PAC targets key races with DeFi on the line

    June 6, 2026
  • Analysis

    NEAR Protocol Sell-Off Intensifies as Price Slips Below $2—A Breakdown Here Could Send It Under $1

    June 6, 2026

    Is MicroStrategy’s 32 BTC Sale the Catalyst Behind a New Bear Market Narrative?

    June 5, 2026

    Bitcoin ETF Outflows Trigger $10 Billion Shock as BTC Tests Critical $60K Support

    June 5, 2026

    Bitcoin traders blamed Saylor’s 32 BTC sale but larger selling pressure built elsewhere

    June 5, 2026

    Dormant Ethereum Whale Resurfaces With Massive ETH Accumulation—Could It Fuel the Next Rally?

    June 5, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is BChat? The Decentralized Messaging App Built for Privacy

    June 2, 2026

    What Is an AI Prompt Injection Attack? The Hidden Threat Hijacking Your Chatbots

    May 31, 2026

    What Is AI Jailbreaking? A Beginner’s Guide to the Cat-and-Mouse Game Behind Every Chatbot

    May 17, 2026

    What’s on the Ethereum Roadmap: Glamsterdam, Hegota and Beyond

    March 30, 2026

    Vitalik wants DeFi price crashes to stop triggering automatic liquidations

    June 4, 2026

    Mt. Gox-linked wallets moved 10,422 BTC, worth roughly $739 million as BTC price slides

    June 4, 2026

    XRP is sitting on a volatility trap as liquidity dries up and leverage builds

    May 27, 2026

    Kraken moves Bitcoin to Chainlink as bridge fears spread across DeFi

    May 16, 2026

    FishWar Partners With RATGPT To Enhance Web3 Gaming Experience With Decentralized AI Network

    June 6, 2026

    A little-known 1,250% rule could lock US banks out of Bitcoin

    June 6, 2026

    Cardano social activity surges as ADA falls under 20 cents to four-year lows

    June 6, 2026

    New Defend Developers PAC targets key races with DeFi on the line

    June 6, 2026
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»North Korean Actor Deploys Novel Malware Campaign Against Crypto Firms
North Korean Actor Deploys Novel Malware Campaign Against Crypto Firms
Security and Privacy

North Korean Actor Deploys Novel Malware Campaign Against Crypto Firms

September 17, 2025No Comments4 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A notorious North Korean affiliated threat actor is targeting crypto firms using multi-stage malware and a novel persistence mechanism, SentinelLabs has reported.

The campaign, dubbed ‘Hidden Risk’, is assessed with high confidence to be perpetrated by the BlueNoroff advanced persistent threat (APT) group, known for financially-motivated attacks. It is designed to target macOS devices.

The campaign starts with a phishing email, with two types of malware dropped following initial infection. The researchers highlighted a novel persistence mechanism in a backdoor which abuses the Zshenv configuration file.

Another notable aspect is the consistent demonstration of attackers’ ability to acquire or hijack valid Apple ‘identified developer’ accounts at will, helping them bypass macOS Gatekeeper and other built-in Apple security technologies.

SentinelLabs said the new campaign, which it observed in October 2024 but likely began as early as July 2024, diverts from other North Korean attacks against crypto-related industries over the past 12 months, many of which involved extensive ‘grooming’ of targets via social media.

“We observe that the Hidden Risk campaign diverts from this strategy taking a more traditional and cruder, though not necessarily any less effective, email phishing approach. Despite the bluntness of the initial infection method, other hallmarks of previous Democratic Republic of North Korea (DPRK)-backed campaigns are evident, both in terms of observed malware artifacts and associated network infrastructure,” the researchers wrote.

This campaign, along with the general increase in macOS crimeware, means all macOS users should harden their security and increase their awareness of potential risks, SentinelLabs said.

The analysis follows a warning by the FBI that cyber actors in North Korea are using sophisticated social engineering campaigns against cryptocurrency operations.

See also  Experty to Reimburse Phished Crypto-Investors

Multi-Stage Malware Campaign

The phishing email that starts the attack contains a link to a malicious application to achieve initial infection.

The application is disguised as a link to a PDF document relating to a cryptocurrency topic such as “Hidden Risk Behind New Surge of Bitcoin Price.” The emails purport to come from a real person in an unrelated industry, claiming to forward a message from a well-known crypto social media influencer.

The phishing email is considered relatively unsophisticated, as it does not contain any personalized information related to the recipient.

The ‘open’ link in the phishing email hides a URL to another domain, delphidigital[.]org. This URL switches to serving the first stage of a malicious application bundle entitled ‘Hidden Risk Behind New Surge of Bitcoin Price.app’.

This is a Mac application written in Swift displaying the same name as the expected PDF. The application bundle was signed and notarized on 19 October, 2024, with the Apple Developer ID “Avantis Regtech Private Limited (2S8XHJ7948)”. The signature has since been revoked by Apple.

On launch, the application downloads the decoy “Hidden Risk” pdf file from a Google Drive share and opens it using the default macOS PDF viewer.

After being written into the moved to /Users/Shared file, the dropper malware downloads and executes a malicious x86-64 binary.

This malicious binary downloaded by the first stage dropper leads the second malware stage, which can only run on Intel architecture Macs or Apple silicon devices with the Rosetta emulation framework installed.

The executable contains a number of identifiable functions, with the overall objective being to act as a backdoor to execute remote commands.

See also  December In Washington Flanked By A Flurry Of Crypto Policy Forums

The SaveAndExec function in the backdoor is responsible for executing any commands received from the command and control (C2) infrastructure. This function creates a random file name of length 6 and changes the file’s permissions and then executes it.

Novel Persistence Technique

The researchers said the backdoor is particularly interesting due to the persistence mechanism used, which abuses the Zshenv configuration file.

Zshenv is one of several optional configuration files used by the Zsh shell.

Infecting the host with a malicious Zshenv file allows for a powerful form of persistence as the file is sourced for all Zsh sessions, including interactive and non-interactive shells, non-login shells and scripts, the researchers noted.

“While this technique is not unknown, it is the first time we have observed it used in the wild by malware authors,” the researchers said.

They added that it has value on modern versions of macOS since Apple introduced user notifications to warn users when a persistence method is installed. Abusing Zshenv does not trigger such a notification in current versions of macOS.

The campaign has been attributed to BlueNoroff following analysis of the actor operated and controlled network infrastructure.

Actor Campaign Crypto deploys Firms Korean malware North
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Crypto firms face July 1 EU cutoff as MiCA grace period ends

June 5, 2026

Crypto PACs go undefeated in June primaries as Fairshake scores bipartisan winning streak

June 5, 2026

Crypto Clarity Act in spotlight for bad-actor provisions as Senate process grinds forward

June 5, 2026

What does the SEC’s new 2030 strategy mean for crypto regulation?

June 5, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Here’s Why Cardano (ADA) Price is Falling to Break the $0.3 Resistance

March 10, 2026

Bitcoin metrics signal a breakout, but a massive “underwater” supply wall is secretly pinning prices below $93,000

December 21, 2025

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

FishWar Partners With RATGPT To Enhance Web3 Gaming Experience With Decentralized AI Network

June 6, 2026

A little-known 1,250% rule could lock US banks out of Bitcoin

June 6, 2026

Cardano social activity surges as ADA falls under 20 cents to four-year lows

June 6, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.