North Korean Hackers Target Web3 Startups with Malware Tactics

Edward Zhou
Edward Zhou

CEO & Co-Founder

 
July 17, 2025
2 min read

North Korean Hackers Target Web3 Startups with NimDoor Malware

North Korean hackers are employing sophisticated tactics to target Web3 and cryptocurrency companies using malicious software known as NimDoor. This malware is a macOS backdoor that poses as a fake Zoom update, tricking victims into installing it. The technique involves phishing links distributed via Calendly and Telegram that lure users into downloading the malware. The malware is designed to steal sensitive data such as browser history and Keychain credentials.

North Korea hackers

Image courtesy of Security Affairs

“DPRK threat actors are utilizing Nim-compiled binaries and multiple attack chains in a campaign targeting Web3 and Crypto-related businesses,” states the analysis published by SentinelOne. The malware employs encrypted communications and is capable of reinfection if killed, mimicking legitimate AppleScript tools to avoid detection.

Attack Mechanism of NimDoor

The attack chain starts with fake Zoom invitations sent via Telegram and Calendly. Victims receive a script named “zoom_sdk_support.scpt,” which is padded with 10,000 lines of whitespace to obscure its malicious intent. This script downloads a second-stage payload from a lookalike domain that mimics legitimate Zoom URLs.

The attackers utilize two Mach-O binaries—one named ‘a’ written in C++ and another called ‘installer’ compiled from Nim. The first binary decrypts malware for data theft, while the second ensures persistence by deploying deceptive Nim binaries.

Hacker in a dark hoody

Image courtesy of CSO Online

“This kind of process injection technique is rare in macOS malware and requires specific entitlements to be performed,” according to researchers. The two payloads maintain persistence by handling termination signals, allowing the malware to redeploy core components.

Multi-Stage Infection Process

The infection process is multi-staged, initially involving a benign file that is executed to disguise the malicious activities. The second Mach-O binary, ‘installer,’ drops additional payloads written in Nim, setting up persistence on infected systems. These include scripts designed to exfiltrate data from browsers and applications like Telegram.

“Earlier this year, we saw threat actors utilizing Nim as well as Crystal,” the SentinelOne researcher notes. “We expect the choice of less familiar languages to become an increasing trend among macOS malware authors due both to their technical advantages and their unfamiliarity to analysts.”

Understanding these unique attack vectors is crucial for organizations in the Web3 and crypto sectors as they navigate the evolving threat landscape. For those interested in protecting their assets and infrastructure, exploring advanced cybersecurity solutions can be a strategic move.

Edward Zhou
Edward Zhou

CEO & Co-Founder

 

CEO & Co-Founder of Gopher Security, leading the development of Post-Quantum cybersecurity technologies and solutions.

Related News

New Industry Report Defines Enterprise Maturity Benchmarks for Zero Trust Identity and Access Architecture
zero trust architecture maturity model

New Industry Report Defines Enterprise Maturity Benchmarks for Zero Trust Identity and Access Architecture

Discover how the new Zero Trust Maturity Model is replacing perimeter-based security with identity-centric frameworks for modern enterprise protection.

By Alan V Gutnov August 5, 2026 5 min read
common.read_full_article
Critical Ruflo MCP Bridge Vulnerability Enables Arbitrary Command Execution and AI Agent Hijacking
CVE-2026-59726

Critical Ruflo MCP Bridge Vulnerability Enables Arbitrary Command Execution and AI Agent Hijacking

Urgent: CVE-2026-59726 'RufRoot' vulnerability exposes Ruflo AI to RCE and agent hijacking. Update to v3.16.3 immediately to prevent total system compromise.

By Divyansh Ingle August 4, 2026 4 min read
common.read_full_article
Rising Endpoint Security Breaches Drive Shift Toward Zero-Trust Architectures for Global Enterprise Remote Access
zero trust architecture maturity model

Rising Endpoint Security Breaches Drive Shift Toward Zero-Trust Architectures for Global Enterprise Remote Access

Discover why Zero Trust is the new baseline for enterprise security. Learn how to combat rising endpoint breaches and secure a distributed, hybrid workforce.

By Brandon Woo August 3, 2026 5 min read
common.read_full_article
NIST Lead Andrew Regenscheid Details Strategic Roadmap for Enterprise Post-Quantum Cryptography Migration
NIST post-quantum cryptography standards

NIST Lead Andrew Regenscheid Details Strategic Roadmap for Enterprise Post-Quantum Cryptography Migration

Learn how to migrate to NIST PQC standards. Expert Andrew Regenscheid details strategies against 'harvest now, decrypt later' quantum threats in 2026.

By Alan V Gutnov July 31, 2026 4 min read
common.read_full_article