#NimDoor
Malware/Tool
2025-07-02 • macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware
NimDoor is a macOS malware suite used by North Korea-linked actors against Web3 and cryptocurrency organizations. Fake Zoom-update social engineering delivered a chain combining AppleScript, Nim binaries, and C++ components. The malware uses process injection, WebSocket communication, and a signal-based persistence technique, and steals sensitive data from compromised Macs. Its use of the relatively uncommon Nim language and a modular execution chain complicates analysis, while the lure targets employees likely to hold valuable cryptocurrency or developer credentials.
-
3
Tagged Reports
-
3
Unique Authors
-
13
Active Days