Close Menu
Tech News VisionTech News Vision
  • Home
  • What’s On
  • Mobile
  • Computers
  • Gadgets
  • Apps
  • Gaming
  • How To
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Trending Now

Cyborgs Are Old (and Maybe Outdated?) Tech in Alien: Earth | SDCC 2025

26 July 2025

Smartphones Launched in India (July 2025): Samsung Galaxy Z Fold 5, Vivo X Fold 5, OnePlus Nord 5 Series, and More

26 July 2025

Longlegs Director Osgood Perkins says Leatherface “Can’t Have a Love Interest” | SDCC 2025

26 July 2025
Facebook X (Twitter) Instagram
  • Privacy
  • Terms
  • Advertise
  • Contact
Facebook X (Twitter) Instagram Pinterest VKontakte
Tech News VisionTech News Vision
  • Home
  • What’s On
  • Mobile
  • Computers
  • Gadgets
  • Apps
  • Gaming
  • How To
  • More
    • Web Stories
    • Global
    • Press Release
Tech News VisionTech News Vision
Home » North Korean Hackers Use NimDoor macOS Malware to Target Web3, Crypto Platforms
Computers

North Korean Hackers Use NimDoor macOS Malware to Target Web3, Crypto Platforms

News RoomBy News Room3 July 2025Updated:3 July 2025No Comments
Facebook Twitter Pinterest LinkedIn Tumblr Email

North Korean hackers are using a special type of malware known as NimDoor to target macOS computers used at Web3 and crypto firms, according to details shared by a cybersecurity research firm. The threat actors are reportedly using bash scripts to collect and transfer sensitive information, such as browser data, iCloud Keychain credentials, and Telegram user data. The attacks rely on social engineering (via a chat platform) and malicious scripts or updates, like others linked to the Democratic People’s Republic of Korea (DPRK).

NimDoor Maintains Access After Malware Termination or System Reboot

Analysis of the NimDoor malware by Sentinel Labs shows that DPRK-linked threat actors are relying on a combination of malicious binaries and scripts that are written in three languages: C++, Nim, and AppleScript. These Nim-compiled binaries are reportedly being used to target Mac computers used in crypto and Web3 firms.

Victims are contacted via messaging apps like Telegram, and the hackers use social engineering to convince a person to join a call using a scheduling service like Calendly. In order to infect the victim’s system, the threat actor sends an email with a malicious “Zoom SDK update” script that installs the malware silently, while allowing it to communicate with a command and control (C2) server.

Once the malware is installed on the target’s Mac computer, the hackers execute bash (terminal) scripts to access and exfiltrate data from browsers like Google Chrome, Microsoft Edge, Arc, Brave, and Firefox. It can also steal iCloud Keychain credentials and Telegram user data from the target’s device.

The cybersecurity research firm also noted that the NimDoor malware feature a “signal-based persistence mechanism” (using SIGINT/SIGTERM handlers) to reinstall itself and continue operating on a target device, even if the malicious process it terminated, or the system is rebooted.

You can read more about the NimDoor malware used to target Web3 and crypto firms on Sentinel Labs’ website, which includes detailed explanations of how the North Korean hackers used novel techniques to gain persistent access to victims’ computers.

The firm also warns that threat actors are increasingly using less popular programming languages to target victims. This is because as they are less familiar to analysts and offer some technical benefits over more widely used languages, while making it difficult to detect and block using existing security measures. . 

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Honor Pad X7 Price, Specifications, Features, Comparison

25 July 2025

Apple Launches Online Tool to Create Custom Wallpapers With Its Logo

25 July 2025

macOS 26, iPadOS 26 and watchOS 26 Public Betas Released With Liquid Glass Design and New Features

25 July 2025

Realme 15 Pro 5G – Price in India, Specifications (24th July 2025)

24 July 2025
Editors Picks

The Walking Dead: Daryl Dixon Season 4 Confirmed to Be Its Last | SDCC 2025

26 July 2025

Google Pixel 10 Pro, Pixel 10 Pro XL Spotted in Moonstone Colourway Alongside Pixel Buds 2a and Pixel Watch 4

26 July 2025

Alien: Rogue Incursion – Part One: Evolved Edition Exclusive Gameplay Trailer Shows Off the ‘Deadlier Xenomorphs’ in 60 FPS | SDCC 2025

26 July 2025

After Imperial Reshapes Marvel’s Cosmic Landscape, This Is What Comes Next | SDCC 2025

26 July 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Trending Now
Tech News Vision
Facebook X (Twitter) Instagram Pinterest Vimeo YouTube
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact
© 2025 Tech News Vision. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.