North Korean Hackers Target Web3 Startups with Malware Tactics

Edward Zhou
Edward Zhou

CEO & Co-Founder

 
July 17, 2025 2 min read

North Korean Hackers Target Web3 Startups with NimDoor Malware

North Korean hackers are employing sophisticated tactics to target Web3 and cryptocurrency companies using malicious software known as NimDoor. This malware is a macOS backdoor that poses as a fake Zoom update, tricking victims into installing it. The technique involves phishing links distributed via Calendly and Telegram that lure users into downloading the malware. The malware is designed to steal sensitive data such as browser history and Keychain credentials.

North Korea hackers

Image courtesy of Security Affairs

“DPRK threat actors are utilizing Nim-compiled binaries and multiple attack chains in a campaign targeting Web3 and Crypto-related businesses,” states the analysis published by SentinelOne. The malware employs encrypted communications and is capable of reinfection if killed, mimicking legitimate AppleScript tools to avoid detection.

Attack Mechanism of NimDoor

The attack chain starts with fake Zoom invitations sent via Telegram and Calendly. Victims receive a script named “zoom_sdk_support.scpt,” which is padded with 10,000 lines of whitespace to obscure its malicious intent. This script downloads a second-stage payload from a lookalike domain that mimics legitimate Zoom URLs.

The attackers utilize two Mach-O binaries—one named ‘a’ written in C++ and another called ‘installer’ compiled from Nim. The first binary decrypts malware for data theft, while the second ensures persistence by deploying deceptive Nim binaries.

Hacker in a dark hoody

Image courtesy of CSO Online

“This kind of process injection technique is rare in macOS malware and requires specific entitlements to be performed,” according to researchers. The two payloads maintain persistence by handling termination signals, allowing the malware to redeploy core components.

Multi-Stage Infection Process

The infection process is multi-staged, initially involving a benign file that is executed to disguise the malicious activities. The second Mach-O binary, ‘installer,’ drops additional payloads written in Nim, setting up persistence on infected systems. These include scripts designed to exfiltrate data from browsers and applications like Telegram.

“Earlier this year, we saw threat actors utilizing Nim as well as Crystal,” the SentinelOne researcher notes. “We expect the choice of less familiar languages to become an increasing trend among macOS malware authors due both to their technical advantages and their unfamiliarity to analysts.”

Understanding these unique attack vectors is crucial for organizations in the Web3 and crypto sectors as they navigate the evolving threat landscape. For those interested in protecting their assets and infrastructure, exploring advanced cybersecurity solutions can be a strategic move.

Edward Zhou
Edward Zhou

CEO & Co-Founder

 

CEO & Co-Founder of Gopher Security, leading the development of Post-Quantum cybersecurity technologies and solutions.

Related News

CVE-2025-15467: Critical OpenSSL RCE and DoS Vulnerability Overview
OpenSSL vulnerability

CVE-2025-15467: Critical OpenSSL RCE and DoS Vulnerability Overview

Urgent: OpenSSL 3.x vulnerable to CVE-2025-15467, enabling pre-auth RCE. Learn affected versions, impact, and immediate mitigation steps. Protect your systems now!

By Divyansh Ingle March 10, 2026 4 min read
common.read_full_article
SolarWinds Patches Critical Web Help Desk RCE Vulnerabilities Now
SolarWinds Web Help Desk

SolarWinds Patches Critical Web Help Desk RCE Vulnerabilities Now

Critical RCE & Auth Bypass flaws in SolarWinds Web Help Desk are fixed! Don't risk it. Update to v2026.1 now to protect your systems. Learn more.

By Edward Zhou March 9, 2026 4 min read
common.read_full_article
AI vs Human Hackers: Who Prevails in 2026 Pen Testing?
AI hacking

AI vs Human Hackers: Who Prevails in 2026 Pen Testing?

Discover the results of a groundbreaking study comparing AI agents and human hackers in web vulnerability exploitation. See who prevails and what it means for your security. Read now!

By Jim Gagnard March 6, 2026 6 min read
common.read_full_article
Vulnerability Exploits Lead Cyber Intrusions in 2026 Trends
vulnerability exploits

Vulnerability Exploits Lead Cyber Intrusions in 2026 Trends

Exploits are now the top intrusion method, outpacing phishing. Discover why rapid vulnerability patching is critical and how to bolster your defenses. Read more!

By Edward Zhou March 4, 2026 4 min read
common.read_full_article