• Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021
No Result
View All Result
CryptoABC.net
No Result
View All Result

North Korean Hackers Exploit Unusual “NimDoor” Malware to Breach Macs

July 4, 2025
in Australian Crypto News
Reading Time: 2min read
0 0
A A
0
North Korean Hackers Exploit Unusual “NimDoor” Malware to Breach Macs
0
SHARES
6
VIEWS
ShareShareShareShareShare
  • North Korea-linked hackers use NimDoor, a Nim-written backdoor, posing as trusted contacts on Telegram to trick victims into installing it via fake Zoom updates.
  • NimDoor’s rare Nim code and AppleScript backdoors evade detection, working across Mac, Windows, and Linux, and bypass Apple’s memory protections for deep access.
  • Once installed, it steals crypto wallet data, browser logins, Telegram keys, and runs keyloggers and infostealers like CryptoBot, exfiltrating data while dodging scanners.

North Korean hackers are stepping up their game with new malware strains targeting Apple devices, zeroing in on crypto firms through a polished social engineering campaign.

Sentinel Labs researchers Phil Stokes and Raffaele Sabato detail the phishing operation in a report published July 2, and their findings show how North Korea-linked actors are pivoting to less common programming languages like Nim, which complicates detection, alongside AppleScript backdoors that infiltrate a target’s system.

The phishing scam goes somewhat like this: the attackers pose as trusted contacts on apps like Telegram, then lure targets into a fake Zoom call through a Google Meet link. There, a bogus “Zoom update” file is awaiting the victim, and when they run it, they’re actually installing a backdoor called NimDoor, built to siphon crypto wallet data and browser credentials from Mac computers.

Related: Crypto Heists Hit Record High in H1 2025 as State-Sponsored Attacks Surge

DPRK Now Using NimDoor

Explained a bit simpler, NimDoor is written in Nim, a rare language that lets hackers deploy the same payload across several operating systems like Mac, Windows, Linux, etc, with little fuss. Unlike more common Go or Rust exploits, Nim’s unusual footprint makes it harder for security tools to flag. 

Although the early stages of the attack follow a familiar DPRK pattern using social engineering, lure scripts and fake updates, the use of Nim-compiled binaries on macOS is a more unusual choice.

Sentinel Labs

The bigger worry is how well the malware burrows into Apple’s defenses. Sentinel’s findings show it bypasses built-in memory protections to embed itself deeper, running keyloggers, screen recorders, clipboard hijackers, and an infostealer named CryptoBot designed to hunt wallet extensions inside browsers.

Then, once active, the payload does several things, like stealing browser logins, packages up system data, grabs Telegram’s local encrypted database and its keys, then slips it all out silently, waiting a full ten minutes to dodge scanners. 

Huntress, another security firm, reported similar incidents last month linked to BlueNoroff, a known North Korean state-backed crew.

Related: Bitcoin’s Three-Month Rally Shows Signs of Fatigue as Profit-Taking Rises

Credit: Source link

ShareTweetSendPinShare
Previous Post

NVIDIA Unveils Data Flywheel Blueprint to Optimize AI Agents

Next Post

Ripple Labs Seeks U.S. Bank Charter to Cement Crypto–Finance Bridge

Next Post
Ripple Labs Seeks U.S. Bank Charter to Cement Crypto–Finance Bridge

Ripple Labs Seeks U.S. Bank Charter to Cement Crypto–Finance Bridge

You might also like

Elon Musk Grok AI Predicts Shocking XRP Price by End of 2026

Elon Musk Grok AI Predicts Shocking XRP Price by End of 2026

June 22, 2026
Nvidia Plans to add Innovation in the Metaverse with Software, Marketplace Deals

NVIDIA’s New AI Tools Accelerate Science From Labs to Space

June 22, 2026
Bank of England Softens Stablecoin Rules With £40 Billion Issuer Cap

Bank of England Softens Stablecoin Rules With £40 Billion Issuer Cap

June 22, 2026
Tom Lee’s BitMine Says ETH Holdings Have Reached 5.67 Millio

Tom Lee’s BitMine Says ETH Holdings Have Reached 5.67 Millio

June 23, 2026
XRP Forms Channel Support That Puts Market In Difficult Spot, But Bulls Still Have A Chance

Ripple And SBI Launch RLUSD Stablecoin In Japan After Regulatory Approval

June 25, 2026
Why Is Crypto Up Today? – October 15, 2025

Crypto News, June 26: Bitcoin Price Retested $58K, Ethereum Touched Double Bottom, MSTR Crashes, $3Billion Outflow – Time to Stack Sats?

June 26, 2026
CryptoABC.net

This is an Australian online news/education portal that aims to provide the latest crypto news, real-time updates, education and reviews within Australia and around the world. Feel free to get in touch with us!

What's New Here!

Bitcoin Slides Toward $58,000 As ETF Outflows And Options Expiry Add Pressure

Bitcoin Slides Toward $58,000 As ETF Outflows And Options Expiry Add Pressure

June 26, 2026
Apple Vision Pro exec to OpenAI, but Polymarket still has Anthropic at 85.5%

Apple Vision Pro exec to OpenAI, but Polymarket still has Anthropic at 85.5%

June 26, 2026

Subscribe Now

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 cryptoabc.net - All rights reserved!

No Result
View All Result
  • Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021

© 2021 cryptoabc.net - All rights reserved!

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.