Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
What's Hot

Labor Secretary Lori Chavez-DeRemer Resigns, Becomes Trump’s Third Cabinet Departure

April 24, 2026

Can ATOM Price Break Above $2 Resistance?

April 24, 2026

Will Ethereum Reach $250,000 Before Bitcoin? Here’s What Needs To Happen

April 24, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    India pushes digital rupee through welfare pilots as BRICS CBDC plan takes shape

    April 24, 2026

    Bitcoin’s Quantum Problem Is Really A Governance Crisis In Disguise: UTXO

    April 24, 2026

    Eric Trump’s American Bitcoin adds 11,298 ASIC miners – ABTC stock surges 8%

    April 24, 2026

    US Military Tests Bitcoin Node for Cybersecurity Research

    April 24, 2026

    Will Ethereum Reach $250,000 Before Bitcoin? Here’s What Needs To Happen

    April 24, 2026

    Ethereum Near Key Zone After 36% Gain

    April 24, 2026

    Bitmine Stakes 61,232 ETH Worth $142M

    April 22, 2026

    Ethereum Targets Lower Range As Resistance Zone Comes Into Play

    April 22, 2026

    Bitcoin Recovery May Not Arrive Until October, Scaramucci Says

    April 24, 2026

    Dogecoin Keeps Getting Capped At This Parallel Channel Level, Analyst Says

    April 24, 2026

    What’s Happening Between ETH And The Financial Systems?

    April 24, 2026

    Could Ripple XRP Power Cross-Border Payments? Russia’s Early Tests Suggest Potential

    April 23, 2026

    Meme Coin Market Faces Imbalance as Supply Rises, Demand Falls

    April 4, 2026

    Crypto Interest Rising Toward Meme Coin Sector

    January 9, 2026

    Memes Market Cap Adds $10B in Days: Fresh Capital or Dead-Cat-Bounce?

    January 5, 2026

    Meme Coin Market Surges Past $45B as Shiba Inu, PEPE, BONK Stage 54% Price Pump

    January 4, 2026

    Labor Secretary Lori Chavez-DeRemer Resigns, Becomes Trump’s Third Cabinet Departure

    April 24, 2026

    Can ATOM Price Break Above $2 Resistance?

    April 24, 2026

    Will Ethereum Reach $250,000 Before Bitcoin? Here’s What Needs To Happen

    April 24, 2026

    Mastercard joins the blockchain security push — why it matters now

    April 24, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Mastercard joins the blockchain security push — why it matters now

    April 24, 2026

    WalletConnect Integrates with TradFi-Focused Chain Canton Network

    April 24, 2026

    Base Tests Azul Upgrade With Multiproofs Ahead of Planned Mainnet Launch

    April 24, 2026

    Pyth Network to determine outcomes in Kalshi’s commodities expansion

    April 24, 2026

    Npm Supply Chain Attack Uses Worm-Like Propagation

    April 24, 2026

    How crypto futures markets are feeding ‘scam coin’ insider pump and dumps

    April 22, 2026

    North Korean Blamed for $290m KelpDAO Crypto Heist

    April 21, 2026

    Chainalysis Flags Critical Blind Spot in DeFi Security as $292M Exploit Bypasses Burn Verification

    April 21, 2026

    Labor Secretary Lori Chavez-DeRemer Resigns, Becomes Trump’s Third Cabinet Departure

    April 24, 2026

    Can ATOM Price Break Above $2 Resistance?

    April 24, 2026

    Will Ethereum Reach $250,000 Before Bitcoin? Here’s What Needs To Happen

    April 24, 2026

    Mastercard joins the blockchain security push — why it matters now

    April 24, 2026
  • Web 3
    1. Gaming
    2. View All

    KuCoin Launches KuCard in Australia, Expanding Real-World Crypto Payments

    April 24, 2026

    REAL and RWA Inc. Partner to Advance Tokenized Asset Infrastructure Amid Growing RWA Demand

    April 24, 2026

    Zach Lowe: Celtics’ offense struggles since Tatum’s return, Luka Doncic’s historic scoring season, and LeBron’s pivotal role in Lakers’ surprise playoff success

    April 24, 2026

    GameFi is effectively dead as 93% of projects collapse

    April 24, 2026

    Labor Secretary Lori Chavez-DeRemer Resigns, Becomes Trump’s Third Cabinet Departure

    April 24, 2026

    Can ATOM Price Break Above $2 Resistance?

    April 24, 2026

    Will Ethereum Reach $250,000 Before Bitcoin? Here’s What Needs To Happen

    April 24, 2026

    Mastercard joins the blockchain security push — why it matters now

    April 24, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    Labor Secretary Lori Chavez-DeRemer Resigns, Becomes Trump’s Third Cabinet Departure

    April 24, 2026

    Justin Sun sues Trump-linked World Liberty over disputed token freeze and governance proposal

    April 24, 2026

    Donald Trump Announces Ceasefire with Iran Extended!

    April 24, 2026

    Tron’s Justin Sun sues Trump-linked World Liberty Financial over frozen assets

    April 24, 2026

    Cardano development teams wants almost $50 million for Bitcoin DeFi and Vision 2030

    April 24, 2026

    Oil tanker attacked after falling for crypto scam granting fake Strait of Hormuz safe passage

    April 21, 2026

    Six years after “DeFi Summer” is the sun already setting on the decentralized finance revolution?

    April 20, 2026

    Bitcoin network activity just hit an 8-year low — has Wall Street replaced retail in the market?

    April 19, 2026

    Labor Secretary Lori Chavez-DeRemer Resigns, Becomes Trump’s Third Cabinet Departure

    April 24, 2026

    Can ATOM Price Break Above $2 Resistance?

    April 24, 2026

    Will Ethereum Reach $250,000 Before Bitcoin? Here’s What Needs To Happen

    April 24, 2026

    Mastercard joins the blockchain security push — why it matters now

    April 24, 2026
  • Analysis

    Can ATOM Price Break Above $2 Resistance?

    April 24, 2026

    Is $2 the Next Target?

    April 24, 2026

    SPK Price Explodes After Breakout, But Overbought Signals Flash Warning

    April 23, 2026

    US Bankers association push for 60 day pause to stop stablecoin rules going live

    April 23, 2026

    STABLE Price Jumps 15% After CEO Spotlight, But Is This Rally Sustainable?

    April 23, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What’s on the Ethereum Roadmap: Glamsterdam, Hegota and Beyond

    March 30, 2026

    What Is Bluesky? The Decentralized Social Media Rival to Elon Musk’s X

    March 27, 2026

    What Is Strategy (MSTR)? The Bitcoin Treasury Company

    February 21, 2026

    What Are Prediction Markets? How Polymarket, Kalshi and Myriad Work

    February 13, 2026

    Over 80% of Bitcoin ETF assets hit Coinbase custody choke point with $74B at risk

    April 13, 2026

    FTX begins $2.2B payout. Can Bitcoin absorb another liquidity test?

    March 31, 2026

    BlinkEx investment platform infrastructure – matching, risk controls, reliability

    March 21, 2026

    Over $2B in “lost” Bitcoin to hit markets this month creating sell pressure within fragile $67k–$74k range

    March 20, 2026

    Labor Secretary Lori Chavez-DeRemer Resigns, Becomes Trump’s Third Cabinet Departure

    April 24, 2026

    Can ATOM Price Break Above $2 Resistance?

    April 24, 2026

    Will Ethereum Reach $250,000 Before Bitcoin? Here’s What Needs To Happen

    April 24, 2026

    Mastercard joins the blockchain security push — why it matters now

    April 24, 2026
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»North Korean Actor Deploys Novel Malware Campaign Against Crypto Firms
North Korean Actor Deploys Novel Malware Campaign Against Crypto Firms
Security and Privacy

North Korean Actor Deploys Novel Malware Campaign Against Crypto Firms

September 17, 2025No Comments4 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A notorious North Korean affiliated threat actor is targeting crypto firms using multi-stage malware and a novel persistence mechanism, SentinelLabs has reported.

The campaign, dubbed ‘Hidden Risk’, is assessed with high confidence to be perpetrated by the BlueNoroff advanced persistent threat (APT) group, known for financially-motivated attacks. It is designed to target macOS devices.

The campaign starts with a phishing email, with two types of malware dropped following initial infection. The researchers highlighted a novel persistence mechanism in a backdoor which abuses the Zshenv configuration file.

Another notable aspect is the consistent demonstration of attackers’ ability to acquire or hijack valid Apple ‘identified developer’ accounts at will, helping them bypass macOS Gatekeeper and other built-in Apple security technologies.

SentinelLabs said the new campaign, which it observed in October 2024 but likely began as early as July 2024, diverts from other North Korean attacks against crypto-related industries over the past 12 months, many of which involved extensive ‘grooming’ of targets via social media.

“We observe that the Hidden Risk campaign diverts from this strategy taking a more traditional and cruder, though not necessarily any less effective, email phishing approach. Despite the bluntness of the initial infection method, other hallmarks of previous Democratic Republic of North Korea (DPRK)-backed campaigns are evident, both in terms of observed malware artifacts and associated network infrastructure,” the researchers wrote.

This campaign, along with the general increase in macOS crimeware, means all macOS users should harden their security and increase their awareness of potential risks, SentinelLabs said.

The analysis follows a warning by the FBI that cyber actors in North Korea are using sophisticated social engineering campaigns against cryptocurrency operations.

See also  Criminal Cryptocurrency Transactions Will Drop by 30% by 2024 - Here's Why

Multi-Stage Malware Campaign

The phishing email that starts the attack contains a link to a malicious application to achieve initial infection.

The application is disguised as a link to a PDF document relating to a cryptocurrency topic such as “Hidden Risk Behind New Surge of Bitcoin Price.” The emails purport to come from a real person in an unrelated industry, claiming to forward a message from a well-known crypto social media influencer.

The phishing email is considered relatively unsophisticated, as it does not contain any personalized information related to the recipient.

The ‘open’ link in the phishing email hides a URL to another domain, delphidigital[.]org. This URL switches to serving the first stage of a malicious application bundle entitled ‘Hidden Risk Behind New Surge of Bitcoin Price.app’.

This is a Mac application written in Swift displaying the same name as the expected PDF. The application bundle was signed and notarized on 19 October, 2024, with the Apple Developer ID “Avantis Regtech Private Limited (2S8XHJ7948)”. The signature has since been revoked by Apple.

On launch, the application downloads the decoy “Hidden Risk” pdf file from a Google Drive share and opens it using the default macOS PDF viewer.

After being written into the moved to /Users/Shared file, the dropper malware downloads and executes a malicious x86-64 binary.

This malicious binary downloaded by the first stage dropper leads the second malware stage, which can only run on Intel architecture Macs or Apple silicon devices with the Rosetta emulation framework installed.

The executable contains a number of identifiable functions, with the overall objective being to act as a backdoor to execute remote commands.

See also  Trump’s White House Has One View of Crypto Legislation. His Family’s Crypto Company Has Another

The SaveAndExec function in the backdoor is responsible for executing any commands received from the command and control (C2) infrastructure. This function creates a random file name of length 6 and changes the file’s permissions and then executes it.

Novel Persistence Technique

The researchers said the backdoor is particularly interesting due to the persistence mechanism used, which abuses the Zshenv configuration file.

Zshenv is one of several optional configuration files used by the Zsh shell.

Infecting the host with a malicious Zshenv file allows for a powerful form of persistence as the file is sourced for all Zsh sessions, including interactive and non-interactive shells, non-login shells and scripts, the researchers noted.

“While this technique is not unknown, it is the first time we have observed it used in the wild by malware authors,” the researchers said.

They added that it has value on modern versions of macOS since Apple introduced user notifications to warn users when a persistence method is installed. Abusing Zshenv does not trigger such a notification in current versions of macOS.

The campaign has been attributed to BlueNoroff following analysis of the actor operated and controlled network infrastructure.

Actor Campaign Crypto deploys Firms Korean malware North
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Npm Supply Chain Attack Uses Worm-Like Propagation

April 24, 2026

KuCoin Launches KuCard in Australia, Expanding Real-World Crypto Payments

April 24, 2026

Crypto Veterans Flip Bullish on Bitcoin As BTC Trades at $78,000 – Here Are Their Price Targets

April 24, 2026

Explosive Class Action Alleges False Advertising and Market Manipulation in Crypto AI Project

April 23, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Bitcoin Holds Steady Ahead of FOMC Decision—Will BTC Price Ignite a Major Rally Next?

October 29, 2025

Novogratz Sees $200K if Trump’s Fed Pick Turns Dovish 

September 27, 2025

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Labor Secretary Lori Chavez-DeRemer Resigns, Becomes Trump’s Third Cabinet Departure

April 24, 2026

Can ATOM Price Break Above $2 Resistance?

April 24, 2026

Will Ethereum Reach $250,000 Before Bitcoin? Here’s What Needs To Happen

April 24, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.