PULSE NAME
macOS NimDoor | North Korean Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware
WHITE DPRK AlienVault 2025-07-04 Modified: 2025-07-04
32
IOCs
MEDIUM VOLUME
DPRK threat actors are targeting Web3 and crypto-related businesses using Nim-compiled binaries and multiple attack chains. The malware, dubbed NimDoor, employs unusual techniques for macOS, including process injection and encrypted WebSocket communications. It uses a novel persistence mechanism leveraging signal handlers and deploys AppleScripts as beacons and backdoors. The attack chain begins with social engineering via Telegram, leading to the execution of malicious scripts and binaries. The malware exfiltrates browser data, Keychain credentials, and Telegram user information. The use of Nim introduces new levels of complexity for analysts, blending complex behavior into binaries with less obvious control flow.
Indicators of Compromise (1 / 32 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 13c07ccb4117bfba9921e45c39b10339 2025-07-04