Going DNS Deep Diving Into GhostCall and GhostHire
2025-11-29 • Whoisxmlapi •
https://circleid.com/posts/going-dns-deep-diving-into-ghostcall-and-ghosthire
BlueNorroff's GhostCall operation targeted technology executives and venture capitalists on macOS by using Telegram-style investment lures and fake Zoom meetings that pushed victims to run a malicious update script. The script downloaded a ZIP payload and enabled theft of crypto wallet data, keychain contents, package-manager and infrastructure details, cloud and DevOps information, API keys, browser credentials, messenger data, Telegram data, and notes. GhostHire used recruitment-themed GitHub repositories disguised as Web3 developer assessments and worked across operating systems to steal sensitive data. Securelist linked GhostCall and GhostHire through shared infrastructure, and the DNS analysis expanded on 39 domain IOCs, suspicious update-themed domains, active resolving IPs, historical WHOIS connections, and DNS traffic involving 1,345 unique client IP addresses.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | bydnib.com | 2025-11-29 | 2025-11-29 |
| IPv4 | 104.168.136.231 | 2025-11-29 | 2025-11-29 |
| IPv4 | 172.236.126.225 | 2025-11-09 | 2025-11-29 |
| IPv4 | 172.236.126.145 | 2025-11-09 | 2025-11-29 |
| IPv4 | 172.236.126.142 | 2025-11-09 | 2025-11-29 |
| DOMAIN | real-update.xyz | 2025-10-28 | 2025-11-29 |
| DOMAIN | system-update.xyz | 2025-10-28 | 2025-11-29 |
| DOMAIN | security-update.xyz | 2025-10-28 | 2025-11-29 |
| DOMAIN | autoupdate.xyz | 2025-10-28 | 2025-11-29 |
| IPv4 | 76.223.54.146 | 2017-05-23 | 2025-11-29 |