logo

DPRK macOS 'NimDoor' Malware Targets Web3, Crypto Platforms

ID: eb0d67cf-7165-52ce-b8ec-e482b6399e3a

STIX ID: report--eb0d67cf-7165-52ce-b8ec-e482b6399e3a

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-07-07

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

NimDoor is a macOS-focused infostealer attributed to DPRK-linked actors that targets Web3 and cryptocurrency users by luring victims via Telegram and fake "Zoom SDK update" scripts; the Nim-compiled binaries exfiltrate Telegram user data, browser information, and Apple Keychain credentials, employ persistence via SIGINT/SIGTERM handlers, use process injection and wss (WebSocket over TLS) for C2, and SentinelOne recommends reviewing included IOCs and exercising caution with unsolicited meeting requests or software updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.