North Korean Hackers Use NimDoor macOS Malware to Target Web3, Crypto Platforms

Threat actors are using social engineering to impersonate trusted contacts and convince targets to install persistent malware on their Mac computers.

Advertisement
Written by David Delima | Updated: 3 July 2025 12:02 IST
Highlights
  • DPRK-linked threat actors are targeting Mac computers at crypto firms
  • The NimDoor malware is persistent and can survive termination, reboots
  • Hackers are using less popular languages to evade detection by analysts

Hackers are using bash scripts to exfiltrate data from Google Chrome and other browsers

Photo Credit: Unsplash/ @firmbee

North Korean hackers are using a special type of malware known as NimDoor to target macOS computers used at Web3 and crypto firms, according to details shared by a cybersecurity research firm. The threat actors are reportedly using bash scripts to collect and transfer sensitive information, such as browser data, iCloud Keychain credentials, and Telegram user data. The attacks rely on social engineering (via a chat platform) and malicious scripts or updates, like others linked to the Democratic People's Republic of Korea (DPRK).

NimDoor Maintains Access After Malware Termination or System Reboot

Analysis of the NimDoor malware by Sentinel Labs shows that DPRK-linked threat actors are relying on a combination of malicious binaries and scripts that are written in three languages: C++, Nim, and AppleScript. These Nim-compiled binaries are reportedly being used to target Mac computers used in crypto and Web3 firms.

Victims are contacted via messaging apps like Telegram, and the hackers use social engineering to convince a person to join a call using a scheduling service like Calendly. In order to infect the victim's system, the threat actor sends an email with a malicious "Zoom SDK update" script that installs the malware silently, while allowing it to communicate with a command and control (C2) server.

Advertisement

Once the malware is installed on the target's Mac computer, the hackers execute bash (terminal) scripts to access and exfiltrate data from browsers like Google Chrome, Microsoft Edge, Arc, Brave, and Firefox. It can also steal iCloud Keychain credentials and Telegram user data from the target's device.

The cybersecurity research firm also noted that the NimDoor malware feature a "signal-based persistence mechanism" (using SIGINT/SIGTERM handlers) to reinstall itself and continue operating on a target device, even if the malicious process it terminated, or the system is rebooted.

You can read more about the NimDoor malware used to target Web3 and crypto firms on Sentinel Labs' website, which includes detailed explanations of how the North Korean hackers used novel techniques to gain persistent access to victims' computers.

Advertisement

The firm also warns that threat actors are increasingly using less popular programming languages to target victims. This is because as they are less familiar to analysts and offer some technical benefits over more widely used languages, while making it difficult to detect and block using existing security measures. . 

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement
Popular Mobile Brands
  1. Motorola Edge 70 5G Price Leaked Ahead of Global Launch
  2. iQOO 15 Confirmed to Launch With This Useful Charging Upgrade
  3. Samsung Galaxy Watch 8 Review: The No-Nonsense Smartwatch
  4. Realme 15x 5G With 7,000mAh Battery Launched in India: See Price
  5. Samsung Reportedly Revives Galaxy S26+ Due to Galaxy S25 Edge's Low Sales
  6. Tata Communications Partners BSNL to Offer eSIM Services Across India
  7. Apple's Next iPad Pro Spotted in Unboxing Video; Design, Features Leaked
  1. James Webb Offers First Glimpse Into How Moons Are Built Around Distant Planets
  2. James Webb Telescope Unveils Hidden Star-Forming Regions in Sagittarius B2
  3. Orionid Meteor Shower 2025: When and How to Watch Stunning Shooting Stars
  4. Million Dollar Listing: India Season 2 Streaming Now on OTT: Know When and Where to Watch it Online.
  5. Dill Bill is Now Streaming Online: Know Everything About its Cast, Story, Release Date, and More
  6. Little Hearts (2025) Telugu OTT Release: What You Need to Know about its Cast, Plot, Trailer, and More
  7. JWST Delivers First-Ever Weather Report of Rogue Brown Dwarf World Glowing With Auroras
  8. Made In India: A Titan Story OTT Release Date: Know When and Where to Watch it Online
  9. Halo Studios to Host a "Deep Dive" on Halo Games in Development This Month
  10. Tata Communications Partners BSNL to Offer eSIM Services Across India
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.