Skip to content

Top Stories

Top Stories

Primary Menu
  • Breaking News
  • UNIT CONVERTER
  • QR Code Generator
  • SEO META TAG GENERATOR
  • Background Remover Tool
  • Image Enhancer Tool
  • Image Converter Tool
  • Image Compressor Tool
  • Keyword Research Tool
  • Paint Tool
  • About Us
  • Contact Us
  • Privacy Policy
HOME PAGE
  • Home
  • Uncategorized
  • N Korean Hackers Drop NimDoor macOS Malware Via Fake Zoom Updates
  • Uncategorized

N Korean Hackers Drop NimDoor macOS Malware Via Fake Zoom Updates

VedVision HeadLines July 3, 2025
N Korean Hackers Drop NimDoor macOS Malware Via Fake Zoom Updates


A new report from SentinelLabs, released on July 2, 2025, reveals a sophisticated cyberattack campaign targeting Web3 and cryptocurrency companies. Threat actors aligned with North Korea are aggressively exploiting macOS systems with a newly discovered malware called NimDoor, utilizing complex, multi-stage attacks and encrypted communications to remain undetected.

The research, authored by Phil Stokes and Raffaele Sabato and shared with Hackread.com, highlights the attackers’ shift towards less common, cross-platform programming languages like Nim. This change complicates efforts to detect and analyse their malicious activities.

The group also uses AppleScript in clever ways, not just for the initial breach but also as simple, hard-to-spot backdoors. Their methods show a clear improvement in staying hidden and persistent, including using encrypted WebSocket (wss) communication and unusual ways to maintain access even after malware is supposedly shut down.

How the Attacks Works

The attacks begin with a familiar social engineering trick: hackers pretend to be trusted contacts on platforms like Telegram, inviting targets to fake Zoom meetings. They send emails with a malicious Zoom SDK update script designed to look legitimate but is actually heavily disguised with thousands of lines of hidden code. This script then downloads more harmful programs from attacker-controlled websites, which often use names similar to real Zoom domains to fool users.

N Korean Hackers Drop NimDoor macOS Malware Via Fake Zoom Updates
The fake Zoom update notification (Credit: SentinelLabs)

Once inside, the infection process becomes multi-layered. The hackers deploy several tools, including a C++ program that injects malicious code into legitimate processes, a rare technique for macOS malware. This allows them to steal sensitive data like browser information, Keychain passwords, shell history, and Telegram chat histories.

According to SentinelLabs’ blog post, they also install the Nim-compiled ‘NimDoor’ malware, which sets up long-term access. This includes a component named “GoogIe LLC” (note the deceptive capital ‘i’ instead of a lowercase ‘L’), which helps the malware blend in. Interestingly, the malware includes a unique feature that triggers its main components and ensures continued access if a user tries to close it or the system reboots.

Another Day, Another North Korean Campaign

SentinelLabs’ analysis shows that these North Korean-aligned actors are constantly developing new ways to bypass security. Their use of Nim, a language that allows them to embed complex behaviours within compiled programs, makes it harder for security experts to understand how the malware works. Additionally, using AppleScript for simple tasks like regularly checking in with their servers helps them avoid using more traditional, easily detectable hacking tools.

The report goes on to show how important it is for companies to strengthen their defences as these threats keep changing. As hackers try out new programming languages and more advanced tactics, cybersecurity researchers need to update how they detect and stop these attacks. SentinelLabs sums it up by calling them “inevitable attacks” that everyone should be ready for.





Source link

Continue Reading

Previous: Bitcoin Suisse Exec Laments EU and Swiss Stablecoin Rules
Next: Big Banks Mull Joint Stablecoin

Related News

Surges to 3-Week High Dominating Soaring B DeFi Lending Market
  • Uncategorized

Surges to 3-Week High Dominating Soaring $56B DeFi Lending Market

VedVision HeadLines July 8, 2025
EV Stocks Poised for Growth Amid Policy Shifts
  • Uncategorized

EV Stocks Poised for Growth Amid Policy Shifts

VedVision HeadLines July 8, 2025
New Report Finds Billions of Leaked Credentials and ULP Files on Dark Web Are Outdated
  • Uncategorized

New Report Finds Billions of Leaked Credentials and ULP Files on Dark Web Are Outdated

VedVision HeadLines July 8, 2025

Recent Posts

  • BBC EastEnders star Heather Peace shares real reason she refused to stop filming scenes despite cancer diagnosis
  • Surges to 3-Week High Dominating Soaring $56B DeFi Lending Market
  • EV Stocks Poised for Growth Amid Policy Shifts
  • Brigitte Macron, Kate Middleton and Queen Camilla display powerful imagery at glitzy gala
  • New Report Finds Billions of Leaked Credentials and ULP Files on Dark Web Are Outdated

Recent Comments

No comments to show.

Archives

  • July 2025
  • June 2025
  • May 2025
  • April 2025

Categories

  • Current Affairs
  • Shopping
  • Uncategorized

You may have missed

BBC EastEnders star Heather Peace shares real reason she refused to stop filming scenes despite cancer diagnosis
  • Current Affairs

BBC EastEnders star Heather Peace shares real reason she refused to stop filming scenes despite cancer diagnosis

VedVision HeadLines July 8, 2025
Surges to 3-Week High Dominating Soaring B DeFi Lending Market
  • Uncategorized

Surges to 3-Week High Dominating Soaring $56B DeFi Lending Market

VedVision HeadLines July 8, 2025
EV Stocks Poised for Growth Amid Policy Shifts
  • Uncategorized

EV Stocks Poised for Growth Amid Policy Shifts

VedVision HeadLines July 8, 2025
Brigitte Macron, Kate Middleton and Queen Camilla display powerful imagery at glitzy gala
  • Current Affairs

Brigitte Macron, Kate Middleton and Queen Camilla display powerful imagery at glitzy gala

VedVision HeadLines July 8, 2025
Copyright © All rights reserved. | MoreNews by AF themes.