#NimDoor

Malware/Tool

2025-07-02 • macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware

NimDoor is a macOS malware suite used by North Korea-linked actors against Web3 and cryptocurrency organizations. Fake Zoom-update social engineering delivered a chain combining AppleScript, Nim binaries, and C++ components. The malware uses process injection, WebSocket communication, and a signal-based persistence technique, and steals sensitive data from compromised Macs. Its use of the relatively uncommon Nim language and a modular execution chain complicates analysis, while the lure targets employees likely to hold valuable cryptocurrency or developer credentials.

Tagged Reports

« Back