North Korean Threat Actors Deploy NimDoor Malware to Target Crypto Wallets on macOS
North Korean hackers have introduced a sophisticated malware strain called NimDoor, specifically designed to compromise Apple devices and steal cryptocurrency wallet credentials. The malware leverages the rare Nim programming language and delayed execution tactics to evade detection, marking a significant escalation in cyber threats targeting digital asset holders.
Attackers initiate contact through trusted messaging platforms like Telegram, posing as legitimate contacts before luring victims into fake Zoom meetings. A malicious file disguised as a Zoom update delivers the payload, which then extracts sensitive data from crypto wallets and browser credentials. Cybersecurity firm SentinelLabs uncovered the campaign, highlighting its precision in bypassing macOS security protocols.
The emergence of NimDoor underscores growing risks for cryptocurrency investors, particularly those storing assets in hot wallets. Its focus on social engineering and evasion techniques reflects North Korea's continued refinement of cyber warfare tactics aimed at financial systems.