North Korean Hackers Target Web3 Startups with Malware Tactics

Edward Zhou
Edward Zhou

CEO & Co-Founder

 
July 17, 2025
2 min read

North Korean Hackers Target Web3 Startups with NimDoor Malware

North Korean hackers are employing sophisticated tactics to target Web3 and cryptocurrency companies using malicious software known as NimDoor. This malware is a macOS backdoor that poses as a fake Zoom update, tricking victims into installing it. The technique involves phishing links distributed via Calendly and Telegram that lure users into downloading the malware. The malware is designed to steal sensitive data such as browser history and Keychain credentials.

North Korea hackers

Image courtesy of Security Affairs

“DPRK threat actors are utilizing Nim-compiled binaries and multiple attack chains in a campaign targeting Web3 and Crypto-related businesses,” states the analysis published by SentinelOne. The malware employs encrypted communications and is capable of reinfection if killed, mimicking legitimate AppleScript tools to avoid detection.

Attack Mechanism of NimDoor

The attack chain starts with fake Zoom invitations sent via Telegram and Calendly. Victims receive a script named “zoom_sdk_support.scpt,” which is padded with 10,000 lines of whitespace to obscure its malicious intent. This script downloads a second-stage payload from a lookalike domain that mimics legitimate Zoom URLs.

The attackers utilize two Mach-O binaries—one named ‘a’ written in C++ and another called ‘installer’ compiled from Nim. The first binary decrypts malware for data theft, while the second ensures persistence by deploying deceptive Nim binaries.

Hacker in a dark hoody

Image courtesy of CSO Online

“This kind of process injection technique is rare in macOS malware and requires specific entitlements to be performed,” according to researchers. The two payloads maintain persistence by handling termination signals, allowing the malware to redeploy core components.

Multi-Stage Infection Process

The infection process is multi-staged, initially involving a benign file that is executed to disguise the malicious activities. The second Mach-O binary, ‘installer,’ drops additional payloads written in Nim, setting up persistence on infected systems. These include scripts designed to exfiltrate data from browsers and applications like Telegram.

“Earlier this year, we saw threat actors utilizing Nim as well as Crystal,” the SentinelOne researcher notes. “We expect the choice of less familiar languages to become an increasing trend among macOS malware authors due both to their technical advantages and their unfamiliarity to analysts.”

Understanding these unique attack vectors is crucial for organizations in the Web3 and crypto sectors as they navigate the evolving threat landscape. For those interested in protecting their assets and infrastructure, exploring advanced cybersecurity solutions can be a strategic move.

Edward Zhou
Edward Zhou

CEO & Co-Founder

 

CEO & Co-Founder of Gopher Security, leading the development of Post-Quantum cybersecurity technologies and solutions.

Related News

New U.S. Directive Sets 2030 Deadline for Contractor Transition to Quantum-Resistant Cryptography
post-quantum cryptography standards

New U.S. Directive Sets 2030 Deadline for Contractor Transition to Quantum-Resistant Cryptography

New federal mandate requires contractors to adopt NIST-approved quantum-resistant cryptography by 2030 to combat 'harvest now, decrypt later' cyber threats.

By Alan V Gutnov July 27, 2026 4 min read
common.read_full_article
New Industry Report Outlines Strategic Defense Frameworks Against Harvest Now, Decrypt Later Quantum Threats
harvest now decrypt later

New Industry Report Outlines Strategic Defense Frameworks Against Harvest Now, Decrypt Later Quantum Threats

Learn how 'Harvest Now, Decrypt Later' quantum threats endanger your data. Discover essential NIST post-quantum migration strategies for your enterprise.

By Brandon Woo July 24, 2026 4 min read
common.read_full_article
NIST Finalizes 2026 Technical Requirements for Post-Quantum Cryptographic Infrastructure Migration and Implementation
NIST post-quantum cryptography standards

NIST Finalizes 2026 Technical Requirements for Post-Quantum Cryptographic Infrastructure Migration and Implementation

NIST finalizes 2026 technical requirements for post-quantum cryptographic migration. Learn the key FIPS standards essential for quantum-resistant infrastructure.

By Alan V Gutnov July 23, 2026 5 min read
common.read_full_article
NIST Post-Quantum Cryptography Standards Formally Adopted for Model Context Protocol Infrastructure Deployments
NIST post-quantum cryptography standards

NIST Post-Quantum Cryptography Standards Formally Adopted for Model Context Protocol Infrastructure Deployments

NIST has finalized post-quantum cryptographic standards. Learn how to implement ML-KEM and ML-DSA to secure your Model Context Protocol (MCP) infrastructure.

By Brandon Woo July 22, 2026 5 min read
common.read_full_article