North Korean Hackers Target Crypto Industry with New macOS Malware
North Korea-linked threat actors have deployed NimDoor, a sophisticated malware targeting macOS systems, in a campaign against Web3 and crypto companies. Compiled in the Nim programming language, the malware's unique structure complicates detection by blending runtime and malicious logic during compilation.
SentinelLabs first observed the attack in April 2025, with subsequent incidents confirmed by multiple security firms. Attackers employ social engineering tactics, impersonating contacts on Telegram and luring victims with fake Zoom update requests. The malware arrives via AppleScript files hosted on spoofed domains, delivering a multi-stage payload from attacker-controlled servers.