Close Menu
Xarkas BlogXarkas Blog
    What's Hot

    Ashes of the Damned Easter Egg Song Guide in Black Ops 7 Zombies

    November 15, 2025

    Five people plead guilty to helping North Koreans infiltrate US companies as ‘remote IT workers’

    November 15, 2025

    Redmi Note 15 Series Launch in India Tipped to Take Place in December: Sale Will Commence in January 2026

    November 15, 2025
    Facebook X (Twitter) Instagram
    Xarkas BlogXarkas Blog
    • Tech News

      Five people plead guilty to helping North Koreans infiltrate US companies as ‘remote IT workers’

      November 15, 2025

      Oura Ring 4 Ceramic review: A colorful glow-up

      November 15, 2025

      Tesla releases detailed safety report after Waymo co-CEO called for more data

      November 15, 2025

      Everything you need to know about the AI chatbot

      November 15, 2025

      A comprehensive list of 2025 tech layoffs

      November 15, 2025
    • Mobiles

      Redmi Note 15 Series Launch in India Tipped to Take Place in December: Sale Will Commence in January 2026

      November 15, 2025

      OPPO Unveils Apex Guard to Redefine Smartphone Quality and Longevity

      November 15, 2025

      Philips Smartphone Officially Teased in India: Philips Pad Air Specifications Surface Online

      November 15, 2025

      Samsung Galaxy S26 Series Camera Specifications Tipped Ahead of Launch

      November 15, 2025

      OnePlus 15 Review: The Power and Speed are Back, But at a Cost

      November 15, 2025
    • Gaming

      Ashes of the Damned Easter Egg Song Guide in Black Ops 7 Zombies

      November 15, 2025

      How to Customize Your Character in Where Winds Meet

      November 15, 2025

      Damaged Heat Sink Locations In ARC Raiders

      November 15, 2025

      City Status (Level) Guide In Anno 117 Pax Romana

      November 15, 2025

      Final Fantasy 14’s 7.4 Update Includes Extra Change To Controversial Feature

      November 15, 2025
    • SEO Tips
    • PC/ Laptops

      Apple Reportedly Reserving OLED Displays for M6 Pro and M6 Max MacBook Pro Models

      November 10, 2025

      Apple Reportedly Working on a Budget MacBook Featuring iPhone Chip: Expected Launch and Price

      November 5, 2025

      Acer Predator Helios Neo 16 AI and 16S AI Gaming Laptops Launched in India: Check Pricing and Specifications

      November 4, 2025

      COLORFUL Launches Rimbook L1: Affordable Laptop For Everyday Use

      November 4, 2025

      Acer Expands Lite Series With New Nitro Lite 16 Laptop in India

      November 3, 2025
    • EV

      Here’s How Much It Costs

      November 15, 2025

      Sodium-Ion Batteries Have Landed In America. The Hard Part Starts Now

      November 15, 2025

      Mazda Begins Testing Its Long-Overdue U.S. EV

      November 14, 2025

      Volkswagen Adds Smartwatch Support For U.S. Vehicles

      November 14, 2025

      TATA.ev expands charging footprint with 14 new manned MegaChargers across AP, Telangana

      November 14, 2025
    • Gadget
    • AI
    Facebook
    Xarkas BlogXarkas Blog
    Home - Featured - North Korean Hackers Use NimDoor macOS Malware to Target Web3, Crypto Platforms
    Featured

    North Korean Hackers Use NimDoor macOS Malware to Target Web3, Crypto Platforms

    KavishBy KavishJuly 3, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    North Korean Hackers Use NimDoor macOS Malware to Target Web3, Crypto Platforms
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    North Korean hackers are using a special type of malware known as NimDoor to target macOS computers used at Web3 and crypto firms, according to details shared by a cybersecurity research firm. The threat actors are reportedly using bash scripts to collect and transfer sensitive information, such as browser data, iCloud Keychain credentials, and Telegram user data. The attacks rely on social engineering (via a chat platform) and malicious scripts or updates, like others linked to the Democratic People’s Republic of Korea (DPRK).

    NimDoor Maintains Access After Malware Termination or System Reboot

    Analysis of the NimDoor malware by Sentinel Labs shows that DPRK-linked threat actors are relying on a combination of malicious binaries and scripts that are written in three languages: C++, Nim, and AppleScript. These Nim-compiled binaries are reportedly being used to target Mac computers used in crypto and Web3 firms.

    Victims are contacted via messaging apps like Telegram, and the hackers use social engineering to convince a person to join a call using a scheduling service like Calendly. In order to infect the victim’s system, the threat actor sends an email with a malicious “Zoom SDK update” script that installs the malware silently, while allowing it to communicate with a command and control (C2) server.

    Once the malware is installed on the target’s Mac computer, the hackers execute bash (terminal) scripts to access and exfiltrate data from browsers like Google Chrome, Microsoft Edge, Arc, Brave, and Firefox. It can also steal iCloud Keychain credentials and Telegram user data from the target’s device.

    The cybersecurity research firm also noted that the NimDoor malware feature a “signal-based persistence mechanism” (using SIGINT/SIGTERM handlers) to reinstall itself and continue operating on a target device, even if the malicious process it terminated, or the system is rebooted.

    You can read more about the NimDoor malware used to target Web3 and crypto firms on Sentinel Labs’ website, which includes detailed explanations of how the North Korean hackers used novel techniques to gain persistent access to victims’ computers.

    The firm also warns that threat actors are increasingly using less popular programming languages to target victims. This is because as they are less familiar to analysts and offer some technical benefits over more widely used languages, while making it difficult to detect and block using existing security measures. . 

    For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who’sThat360 on Instagram and YouTube.


    Honor Watch 5 Ultra Launched With eSIM Support, ECG Tracking, Up to 15 Days Battery Life





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Kavish
    • Website

    Related Posts

    Ashes of the Damned Easter Egg Song Guide in Black Ops 7 Zombies

    November 15, 2025

    Five people plead guilty to helping North Koreans infiltrate US companies as ‘remote IT workers’

    November 15, 2025

    Redmi Note 15 Series Launch in India Tipped to Take Place in December: Sale Will Commence in January 2026

    November 15, 2025

    How to Customize Your Character in Where Winds Meet

    November 15, 2025

    Oura Ring 4 Ceramic review: A colorful glow-up

    November 15, 2025

    Tesla releases detailed safety report after Waymo co-CEO called for more data

    November 15, 2025

    Comments are closed.

    Top Reviews
    Editors Picks

    Ashes of the Damned Easter Egg Song Guide in Black Ops 7 Zombies

    November 15, 2025

    Five people plead guilty to helping North Koreans infiltrate US companies as ‘remote IT workers’

    November 15, 2025

    Redmi Note 15 Series Launch in India Tipped to Take Place in December: Sale Will Commence in January 2026

    November 15, 2025

    How to Customize Your Character in Where Winds Meet

    November 15, 2025
    About Us
    About Us

    Email Us: info@xarkas.com

    Facebook Pinterest
    © 2025 . Designed by Xarkas Technologies.
    • Home
    • Mobiles
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.