logo

macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware

Threat Score
85/100

Date Published: 2025-07-02

Date Updated: 2026-07-27

Author: Phil Stokes & Raffaele Sabato

...
...

SentinelLABS describes 'NimDoor', a DPRK-aligned multi-stage macOS campaign targeting Web3/crypto firms that uses social-engineered fake Zoom update AppleScripts to deploy C++ and Nim binaries, AppleScript beacons, and Bash exfiltration scripts; notable techniques include Nim-compiled payloads, process injection into spawned binaries using macOS entitlements, wss-based C2 communications, a novel signal-handler persistence mechanism, and comprehensive IOCs to aid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.