Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
What's Hot

Panic selling sends Bitcoin below $60K once again – The pressure piles on!

June 26, 2026

USDT gets a Brazil payment route to 170 million people by making crypto disappear

June 26, 2026

Worldcoin’s breakdown may be the start of a bigger fall – Here’s why

June 26, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Panic selling sends Bitcoin below $60K once again – The pressure piles on!

    June 26, 2026

    Strategy for Surviving Bitcoin’s Market Challenges

    June 26, 2026

    Majors lead a broad crypto selloff as tech stocks tumble

    June 26, 2026

    Strategy (MSTR) Drops Down 25% In Five Days As BTC Crashes

    June 26, 2026

    Tether Surpasses Ethereum: A Historic Shift

    June 26, 2026

    Ethereum faces renewed selling pressure: Can key support hold this time?

    June 26, 2026

    Ethereum whales dump 19,441 ETH – Can bulls defend $1.5K support?

    June 25, 2026

    Will Bitcoin and Ethereum Price Recover? $11.8B Options Expiry Could Decide Next Move

    June 25, 2026

    Worldcoin’s breakdown may be the start of a bigger fall – Here’s why

    June 26, 2026

    Bitcoin ETP Holdings Hit Record Drawdown As K33 Flags Outflows

    June 26, 2026

    From Ronin to WazirX: Why 55% of ‘DeFi hacks’ have NOTHING to do with code!

    June 26, 2026

    AAVE price jumps 15% – Can $40.69M in protocol fees sustain the breakout?

    June 25, 2026

    Dogecoin Cash Files U.S. Patent for DOGP Blockchain Framework

    June 15, 2026

    How SIREN Went From AI Memecoin to Boom-and-Bust

    June 8, 2026

    Meme Coin Market Faces Imbalance as Supply Rises, Demand Falls

    April 4, 2026

    Crypto Interest Rising Toward Meme Coin Sector

    January 9, 2026

    Panic selling sends Bitcoin below $60K once again – The pressure piles on!

    June 26, 2026

    USDT gets a Brazil payment route to 170 million people by making crypto disappear

    June 26, 2026

    Worldcoin’s breakdown may be the start of a bigger fall – Here’s why

    June 26, 2026

    Strategy for Surviving Bitcoin’s Market Challenges

    June 26, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Merck and Hashgraph Group launch Hedera-based product passport for EU compliance

    June 12, 2026

    COTI and Midnight Foundation Partner to Advance the Global Privacy Ecosystem

    June 11, 2026

    Cardano Gets Exposure From Olympics Committee

    June 11, 2026

    How Privacy and Composability Trade-Offs Differ

    June 11, 2026

    Microsoft Warns of New USB-Based Malware Targeting Crypto Users

    June 21, 2026

    Fake GitHub Stars and AI Videos Mask a Crypto Clipper

    June 18, 2026

    Zcash Climbs 80% Since June 5 as Traders Shrug off Orchard Bug Fears – Bitcoin News

    June 18, 2026

    Rokarolla Trojan Combines Banking Fraud With Device Surveillance

    June 16, 2026

    Panic selling sends Bitcoin below $60K once again – The pressure piles on!

    June 26, 2026

    USDT gets a Brazil payment route to 170 million people by making crypto disappear

    June 26, 2026

    Worldcoin’s breakdown may be the start of a bigger fall – Here’s why

    June 26, 2026

    Strategy for Surviving Bitcoin’s Market Challenges

    June 26, 2026
  • Web 3
    1. Gaming
    2. View All

    NFT Marketplace Volume Is Concentrating Around the Biggest Players

    June 26, 2026

    Loaded Lions’ Mane City Mobile Heads to iOS and Android as Sign-Ups Begin

    June 23, 2026

    Nexus Acquires Homegrown App Marketplace One Store, Expanding into Global Web3 Game Hub

    June 21, 2026

    GoMining Rolls Out GoBTC Pay SDK for Bitcoin Merchant Payments

    June 20, 2026

    Panic selling sends Bitcoin below $60K once again – The pressure piles on!

    June 26, 2026

    USDT gets a Brazil payment route to 170 million people by making crypto disappear

    June 26, 2026

    Worldcoin’s breakdown may be the start of a bigger fall – Here’s why

    June 26, 2026

    Strategy for Surviving Bitcoin’s Market Challenges

    June 26, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    Russia creates crypto sanctions loophole, but cash-out routes remain ringfenced

    June 26, 2026

    Why Europe is struggling to give Binance the MiCA license it needs

    June 26, 2026

    Cynthia Lummis gave CLARITY Act a July promise, but it still needs a Senate path

    June 26, 2026

    Crypto finally has a CLARITY Act date – delivery now depends on seven Senate Democrats

    June 24, 2026

    USDT gets a Brazil payment route to 170 million people by making crypto disappear

    June 26, 2026

    UK bond fund ownership records move onto Ethereum and Solana accessible 24/7

    June 26, 2026

    Chainlink’s latest stablecoin push targets the capital stuck in bank FX settlement

    June 25, 2026

    Latest bear market victim shows how quickly DeFi users are left behind when crypto projects move on

    June 24, 2026

    Panic selling sends Bitcoin below $60K once again – The pressure piles on!

    June 26, 2026

    USDT gets a Brazil payment route to 170 million people by making crypto disappear

    June 26, 2026

    Worldcoin’s breakdown may be the start of a bigger fall – Here’s why

    June 26, 2026

    Strategy for Surviving Bitcoin’s Market Challenges

    June 26, 2026
  • Analysis

    Hyperliquid Whales Buy the Dip — Can HYPE Price Avoid a Breakdown Below $60?

    June 26, 2026

    Solana hits $1B in weekly tokenized stock trading as demand for hard-to-access equities surge

    June 26, 2026

    Ethereum Price Preparing for a Strong Breakout—Here’s Why a Rise Above $2000 is Imminent

    June 26, 2026

    SEI Price Rebounds, but the Long-Term Trend Remains Bearish — What’s Next for SEI?

    June 25, 2026

    Bitcoin Price Trends After Recent Correction

    June 25, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is BChat? The Decentralized Messaging App Built for Privacy

    June 2, 2026

    What Is an AI Prompt Injection Attack? The Hidden Threat Hijacking Your Chatbots

    May 31, 2026

    What Is AI Jailbreaking? A Beginner’s Guide to the Cat-and-Mouse Game Behind Every Chatbot

    May 17, 2026

    What’s on the Ethereum Roadmap: Glamsterdam, Hegota and Beyond

    March 30, 2026

    HYPE ETFs quietly pulled $161M in one month as Wall Street buys crypto’s on-chain exchange bet

    June 15, 2026

    Crypto exchanges are opening a two-front war for the stock market

    June 12, 2026

    Crypto’s killer app may be selling stocks after its own tokens failed retail

    June 10, 2026

    Vitalik wants DeFi price crashes to stop triggering automatic liquidations

    June 4, 2026

    Panic selling sends Bitcoin below $60K once again – The pressure piles on!

    June 26, 2026

    USDT gets a Brazil payment route to 170 million people by making crypto disappear

    June 26, 2026

    Worldcoin’s breakdown may be the start of a bigger fall – Here’s why

    June 26, 2026

    Strategy for Surviving Bitcoin’s Market Challenges

    June 26, 2026
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»North Korean Actor Deploys Novel Malware Campaign Against Crypto Firms
North Korean Actor Deploys Novel Malware Campaign Against Crypto Firms
Security and Privacy

North Korean Actor Deploys Novel Malware Campaign Against Crypto Firms

September 17, 2025No Comments4 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A notorious North Korean affiliated threat actor is targeting crypto firms using multi-stage malware and a novel persistence mechanism, SentinelLabs has reported.

The campaign, dubbed ‘Hidden Risk’, is assessed with high confidence to be perpetrated by the BlueNoroff advanced persistent threat (APT) group, known for financially-motivated attacks. It is designed to target macOS devices.

The campaign starts with a phishing email, with two types of malware dropped following initial infection. The researchers highlighted a novel persistence mechanism in a backdoor which abuses the Zshenv configuration file.

Another notable aspect is the consistent demonstration of attackers’ ability to acquire or hijack valid Apple ‘identified developer’ accounts at will, helping them bypass macOS Gatekeeper and other built-in Apple security technologies.

SentinelLabs said the new campaign, which it observed in October 2024 but likely began as early as July 2024, diverts from other North Korean attacks against crypto-related industries over the past 12 months, many of which involved extensive ‘grooming’ of targets via social media.

“We observe that the Hidden Risk campaign diverts from this strategy taking a more traditional and cruder, though not necessarily any less effective, email phishing approach. Despite the bluntness of the initial infection method, other hallmarks of previous Democratic Republic of North Korea (DPRK)-backed campaigns are evident, both in terms of observed malware artifacts and associated network infrastructure,” the researchers wrote.

This campaign, along with the general increase in macOS crimeware, means all macOS users should harden their security and increase their awareness of potential risks, SentinelLabs said.

The analysis follows a warning by the FBI that cyber actors in North Korea are using sophisticated social engineering campaigns against cryptocurrency operations.

See also  Interview: Analyzing the Hidden Costs of Cybercrime

Multi-Stage Malware Campaign

The phishing email that starts the attack contains a link to a malicious application to achieve initial infection.

The application is disguised as a link to a PDF document relating to a cryptocurrency topic such as “Hidden Risk Behind New Surge of Bitcoin Price.” The emails purport to come from a real person in an unrelated industry, claiming to forward a message from a well-known crypto social media influencer.

The phishing email is considered relatively unsophisticated, as it does not contain any personalized information related to the recipient.

The ‘open’ link in the phishing email hides a URL to another domain, delphidigital[.]org. This URL switches to serving the first stage of a malicious application bundle entitled ‘Hidden Risk Behind New Surge of Bitcoin Price.app’.

This is a Mac application written in Swift displaying the same name as the expected PDF. The application bundle was signed and notarized on 19 October, 2024, with the Apple Developer ID “Avantis Regtech Private Limited (2S8XHJ7948)”. The signature has since been revoked by Apple.

On launch, the application downloads the decoy “Hidden Risk” pdf file from a Google Drive share and opens it using the default macOS PDF viewer.

After being written into the moved to /Users/Shared file, the dropper malware downloads and executes a malicious x86-64 binary.

This malicious binary downloaded by the first stage dropper leads the second malware stage, which can only run on Intel architecture Macs or Apple silicon devices with the Rosetta emulation framework installed.

The executable contains a number of identifiable functions, with the overall objective being to act as a backdoor to execute remote commands.

See also  Ransomware Threat Shifts from US to EMEA and APAC

The SaveAndExec function in the backdoor is responsible for executing any commands received from the command and control (C2) infrastructure. This function creates a random file name of length 6 and changes the file’s permissions and then executes it.

Novel Persistence Technique

The researchers said the backdoor is particularly interesting due to the persistence mechanism used, which abuses the Zshenv configuration file.

Zshenv is one of several optional configuration files used by the Zsh shell.

Infecting the host with a malicious Zshenv file allows for a powerful form of persistence as the file is sourced for all Zsh sessions, including interactive and non-interactive shells, non-login shells and scripts, the researchers noted.

“While this technique is not unknown, it is the first time we have observed it used in the wild by malware authors,” the researchers said.

They added that it has value on modern versions of macOS since Apple introduced user notifications to warn users when a persistence method is installed. Abusing Zshenv does not trigger such a notification in current versions of macOS.

The campaign has been attributed to BlueNoroff following analysis of the actor operated and controlled network infrastructure.

Actor Campaign Crypto deploys Firms Korean malware North
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

USDT gets a Brazil payment route to 170 million people by making crypto disappear

June 26, 2026

Majors lead a broad crypto selloff as tech stocks tumble

June 26, 2026

Russia creates crypto sanctions loophole, but cash-out routes remain ringfenced

June 26, 2026

Tokenized SpaceX stocks hit by $50M in liquidations as crypto leverage reaches Wall Street

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

IMF lays out guidelines for addressing stablecoin risks, beyond regulations

December 7, 2025

Bitcoin Hits New ATH, But Morgan Stanley Caps Crypto Allocation at 4%

October 7, 2025

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Panic selling sends Bitcoin below $60K once again – The pressure piles on!

June 26, 2026

USDT gets a Brazil payment route to 170 million people by making crypto disappear

June 26, 2026

Worldcoin’s breakdown may be the start of a bigger fall – Here’s why

June 26, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.