216.73.217.22

macOS NimDoor | North Korean Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware

· Published 04/07/2025 09:39 · Modified 04/07/2025 10:14

Export JSON

Essential information

Published
04/07/2025 09:39
Modified
04/07/2025 10:14
Tags
2025-07-04 applescript cryptocurrency macos nimdoor process injection web3 websocket
Related entities
9 observables, 1 intrusion sets (apt), 18 techniques (mitre), 1 malware, 2 others

Description

DPRK threat actors are targeting and crypto-related businesses using Nim-compiled binaries and multiple attack chains. The malware, dubbed , employs unusual techniques for , including and encrypted communications. It uses a novel persistence mechanism leveraging signal handlers and deploys AppleScripts as beacons and backdoors. The attack chain begins with social engineering via Telegram, leading to the execution of malicious scripts and binaries. The malware exfiltrates browser data, Keychain credentials, and Telegram user information. The use of Nim introduces new levels of complexity for analysts, blending complex behavior into binaries with less obvious control flow.

External references