Watch out – that amazing job offer could actually just be a crypto-stealing scam, Microsoft warns
The BlueNoroff cybercrime campaign appears to be going from strenght to strenght after Microsoft spotted yet another criminal campaign it attributed to the North Korean hackers.
Redmond’s security pros recently found BlueNoroff (a part of the Lazarus Group advanced persistent threat, which it calls Sapphire Sleet) impersonating skills assessment portals and using them to steal people’s sensitive data or have them download malware.
“Sapphire Sleet typically finds targets on platforms like LinkedIn and uses lures related to skills assessment,” the Microsoft Threat Intelligence team said on X. “The threat actor then moves successful communications with targets to other platforms.”
Distributing malware
BlueNoroff, but also Lazarus as a whole, is a threat actor that’s been seen using fake job ads and targeting professionals in the cryptocurrency industry for years now. With that in mind, the latest campaign that includes skills assessment portals is a “shift in the persistent actor’s tactics,” Microsoft said.
Late last week, security researchers from Jamf warned of a new macOS malware, called ObjCShellz, which was developed and distributed by BlueNoroff. It greatly overlaps with another macOS malware known as RustBucket.
Microsoft said BlueNoroff usually distributed malware by sending malicious attachments or embedded links to pages hosted on GitHub. However, Microsoft’s quick reactions to remove these threats forced Sapphire Sleet to create a new network of websites used to distribute the malware, the researchers claim.
“Several malicious domains and subdomains host these websites, which entice recruiters to register for an account,” the company added. “The websites are password-protected to impede analysis.”
Lazarus Group is suspected to be under the direct command of the North Korean government. Its goals are not always the same, but are usually linked to stealing cryptocurrencies from targets in the West. The money, some sources are saying, are being used to sustain the government and build the nuclear weapons program
More from TechRadar Pro
The BlueNoroff cybercrime campaign appears to be going from strenght to strenght after Microsoft spotted yet another criminal campaign it attributed to the North Korean hackers. Redmond’s security pros recently found BlueNoroff (a part of the Lazarus Group advanced persistent threat, which it calls Sapphire Sleet) impersonating skills assessment portals…
Recent Posts
- Google Wallet ID passes will be available in select EU states this summer
- Shokz upgraded its open earbuds with better sound and a lighter design
- Shokz says its clip-on OpenDots 2 earbuds focus on improved volume and bass
- How to watch England vs New Zealand: TV Channels, Full Schedule & 1st Test Preview
- Nomad Goods Promo Codes: Get 25% Off in June 2026
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023