Going DNS Deep Diving Into GhostCall and GhostHire

2025-11-29 Whoisxmlapi

https://circleid.com/posts/going-dns-deep-diving-into-ghostcall-and-ghosthire

Thumbnail for Going DNS Deep Diving Into GhostCall and GhostHire

BlueNorroff's GhostCall operation targeted technology executives and venture capitalists on macOS by using Telegram-style investment lures and fake Zoom meetings that pushed victims to run a malicious update script. The script downloaded a ZIP payload and enabled theft of crypto wallet data, keychain contents, package-manager and infrastructure details, cloud and DevOps information, API keys, browser credentials, messenger data, Telegram data, and notes. GhostHire used recruitment-themed GitHub repositories disguised as Web3 developer assessments and worked across operating systems to steal sensitive data. Securelist linked GhostCall and GhostHire through shared infrastructure, and the DNS analysis expanded on 39 domain IOCs, suspicious update-themed domains, active resolving IPs, historical WHOIS connections, and DNS traffic involving 1,345 unique client IP addresses.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN bydnib.com 2025-11-29 2025-11-29
IPv4 104.168.136.231 2025-11-29 2025-11-29
IPv4 172.236.126.225 2025-11-09 2025-11-29
IPv4 172.236.126.145 2025-11-09 2025-11-29
IPv4 172.236.126.142 2025-11-09 2025-11-29
DOMAIN real-update.xyz 2025-10-28 2025-11-29
DOMAIN system-update.xyz 2025-10-28 2025-11-29
DOMAIN security-update.xyz 2025-10-28 2025-11-29
DOMAIN autoupdate.xyz 2025-10-28 2025-11-29
IPv4 76.223.54.146 2017-05-23 2025-11-29

Related Actors

Related Reports

« Back