attacking business leaders using Windows and MacOS with AI tools

NGUYỄN ĐĂNG |

Two targeted AI-based cyberattack campaigns have just been discovered, targeting many business organizations in Asia and Europe.

On December 9, the Global Research and Analysis Team (GReAT) of cybersecurity company Kaspersky revealed the latest activities of the APT BlueNoroff holiday group through two sophisticated targeted attack campaigns GhostCall and GhostHire.

These campaigns target Web3 and cryptocurrency organizations in India, Turkey, Australia and many countries in Europe and Asia, and have been taking place since at least April 2025.

The GhostCall and GhostHire campaigns are said to use new breaking techniques and custom-designed malware, aiming to penetrate developers' systems and attack senior leaders of blockchain organizations and businesses. These attacks mainly targeted the MacOS and Windows operating systems, and were coordinated through a unified command- control infrastructure.

The use of generative AI has helped BlueNoroff speed up the development of malware and refine attack techniques. The attacker added new programming languages and more features to make detection and analysis more difficult. AI also helps attack groups manage and expand operations more effectively, making the sophistication and range of attacks even higher.

Since previous campaigns, the attack groups targeting tactics have developed beyond the scope of stealing cryptocurrency or browser login information, said Omar Amin, senior security expert at Kaspersky GReAT. The use of generative AI has accelerated this process, making it easier for them to develop malware and reduce operating costs, expanding the scope of attacks.

To protect against attacks like GhostCall and GhostHire, organizations are recommended to take the following measures:

- Be careful with attractive offers or investment proposals. Always verify the identity of any new contacts, especially if they access them via Telegram, LinkedIn or other social media platforms. Use authenticated and secure internal communication channels for exchanges containing sensitive information.

- Always consider the possibility that an acquaintance's account has been taken over. Verify through another communication channel before opening any file or link, and make sure the domain name you are accessing is the correct correct official name. Avoid running unverified code or commands just to correct the error.

- Use cybersecurity solutions to provide real-time protection, threat monitoring, investigation and quick response capabilities for businesses of all sizes and fields.

- Use Managed Security Services, providing solutions to comprehensively resolve incidents: from detecting threats to continuous protection and overcoming consequences, helping businesses fight sophisticated attacks, investigating incidents and adding expertise, even when businesses lack specialized personnel in charge of cyber security.

- Equip the information security team (InfoSec) with the ability to closely observe the threats targeting the organization.

NGUYỄN ĐĂNG
RELATED NEWS

Millions of customers may have their information exposed due to cyber attacks at airports

|

A cyber attack targeting a technology service provider at Dublin Airport (Ireland) is believed to have leaked the data of millions of passengers.

Vietnamese businesses at risk of cyber attacks for not updating security patches

|

Many security vulnerabilities in the network of Vietnamese enterprises have not been fixed, making them vulnerable to cyber attacks.

Warning of cyber attack targeting hotel

|

Cybersecurity company Kaspersky has warned travelers that their credit card information "can be at risk" after a series of cyber attacks on hotels.

Launching an emulation movement among union members, workers, and trade unions at all levels in 2026

|

The Vietnam General Confederation of Labor launched an emulation movement among union members, workers and trade unions at all levels in 2026 with many specific contents.

Banning Ring Road 1 motorbikes: Deputy Director of Hanoi Department of Construction talks about support levels for people

|

To make people and businesses feel secure in converting to green vehicles, Hanoi is studying and implementing a comprehensive support policy system.

Forecast of the path of the new low pressure area in the next 24 hours

|

According to the meteorological agency, in the next 24 hours, the low pressure area is forecast to move west-southwest, affecting the weather in the South China Sea.

Public electric bicycles run 90 km per charge, Hanoi has more options to replace gasoline motorbikes

|

Hanoi - In the context of Hanoi preparing to limit gasoline motorbikes in the Ring Road 1 area, public electric bicycles are expected to reduce emission pressure in the inner city.

Request to report the case of the undelivered Song Than reservoir cracked and leaking in Khanh Hoa

|

Khanh Hoa - The design consultancy unit is reviewing and comprehensively assessing the Song Coan reservoir after discovering the phenomenon of leakage and cracking in the dam body.

Millions of customers may have their information exposed due to cyber attacks at airports

HẠO THIÊN (THEO Cybernews) |

A cyber attack targeting a technology service provider at Dublin Airport (Ireland) is believed to have leaked the data of millions of passengers.

Vietnamese businesses at risk of cyber attacks for not updating security patches

NGUYỄN ĐĂNG |

Many security vulnerabilities in the network of Vietnamese enterprises have not been fixed, making them vulnerable to cyber attacks.

Warning of cyber attack targeting hotel

NGUYỄN ĐĂNG |

Cybersecurity company Kaspersky has warned travelers that their credit card information "can be at risk" after a series of cyber attacks on hotels.