Skip to content

Top Stories

Top Stories

Primary Menu
  • Breaking News
  • UNIT CONVERTER
  • QR Code Generator
  • SEO META TAG GENERATOR
  • Background Remover Tool
  • Image Enhancer Tool
  • Image Converter Tool
  • Image Compressor Tool
  • Keyword Research Tool
  • Paint Tool
  • About Us
  • Contact Us
  • Privacy Policy
HOME PAGE
  • Home
  • Uncategorized
  • New macOS Malware Uses Process Injection and Remote Access to Steal Keychain Credentials
  • Uncategorized

New macOS Malware Uses Process Injection and Remote Access to Steal Keychain Credentials

VedVision HeadLines July 2, 2025
New macOS Malware Uses Process Injection and Remote Access to Steal Keychain Credentials


A sophisticated campaign by North Korean (DPRK)-aligned threat actors targeting Web3 and cryptocurrency businesses has been uncovered, showcasing an alarming evolution in macOS malware tactics.

According to detailed analysis by SentinelLABS, alongside corroborating reports from Huntabil.IT and Huntress, the attackers deploy a multi-stage attack chain featuring Nim-compiled binaries, process injection techniques, and encrypted remote communications.

DPRK Threat Actors Target Web3

Dubbed “NimDoor,” this malware family leverages an eclectic mix of AppleScripts, Bash scripts, and binaries written in C++ and Nim to infiltrate systems, establish persistence, and exfiltrate sensitive data such as Keychain credentials, browser information, and Telegram user data.

macOS Malware
The AesTrans function is a wrapper of CCCrypt

First observed in targeted attacks in April 2025, this campaign highlights the growing complexity of threats aimed at macOS users in high-value industries.

The attack begins with a familiar social engineering tactic: impersonating a trusted contact via Telegram to lure victims into running a fake “Zoom SDK update script” hosted on deceptive domains mimicking legitimate Zoom infrastructure, such as support.us05web-zoom[.]forum.

This initial AppleScript retrieves secondary payloads, setting off two independent execution chains involving C++ and Nim binaries.

A notable C++ binary, identified as “a” or “InjectWithDyldArm64,” employs a rare process injection technique on macOS, requiring specific entitlements like com.apple.security.cs.debugger to inject malicious code into a benign process.

Persistence Mechanisms

The injected code, housed in a binary named “trojan1_arm64,” communicates with command-and-control (C2) servers using wss (TLS-encrypted WebSocket protocol), an uncommon choice for macOS malware, to receive commands and exfiltrate data.

Concurrently, Nim-compiled binaries like “installer,” “GoogIe LLC,” and “CoreKitAgent” orchestrate long-term persistence, utilizing a groundbreaking signal-based mechanism that intercepts SIGINT and SIGTERM signals to reinstall components upon termination or system reboot.

Additionally, Bash scripts like “upl” and “tlgrm” systematically steal browser data from applications like Chrome and Firefox, alongside Keychain credentials and Telegram databases, compressing and uploading them to C2 servers such as dataupload[.]store.

macOS Malware
Targeted browsers in the upl script

The use of Nim, a lesser-known programming language, introduces unique challenges for defenders due to its ability to execute functions at compile time, obscuring control flow and blending malicious logic with runtime code.

AppleScripts further serve as lightweight beacons and backdoors, contacting C2 servers like writeup[.]live every 30 seconds to relay system information and execute remote commands.

This blend of cross-platform languages, native macOS scripting, and innovative persistence techniques such as leveraging signal handlers and asynchronous execution demonstrates a clear intent to evade traditional security measures.

According to the Report, SentinelLABS warns that the adoption of unconventional languages like Nim and Crystal by threat actors is likely to increase, urging analysts and detection engineers to deepen their understanding of these tools.

As macOS becomes a more frequent target for state-sponsored actors, particularly in lucrative sectors like cryptocurrency, the need for advanced threat hunting and behavioral detection grows ever more critical to counter these evolving attack methodologies.

Indicators of Compromise (IoC)

Category Indicator Description
Domains dataupload[.]store upl/tlgrm C2
firstfromsep[.]online netchk C2
safeup[.]store CoreKit C2
FilePaths ~/Library/Application Support/Google LLC/GoogIe LLC Payload location
~/.ses AppleScript beacon
Binaries (SHA-1) 5b16e9d6e92be2124ba496bf82d38fb35681c7ad a (universal)
Scripts (SHA-1) 023a15ac687e2d2e187d03e9976a89ef5f6c1617 zoom_sdk_support.scpt

Exclusive Webinar Alert: Harnessing Intel® Processor Innovations for Advanced API Security – Register for Free



Source link

Continue Reading

Previous: CME, GS & MKTX Could Surge Higher
Next: Sean 'Diddy' Combs trial live updates: Jury set to resume deliberations after reaching verdict on 4 of 5 counts – Yahoo

Related News

US risks financial crisis ahead of midterm elections: former IMF official
  • Uncategorized

US risks financial crisis ahead of midterm elections: former IMF official

VedVision HeadLines July 13, 2025
Will It Blast Through 5,000 Or Slip Back To 0,000?
  • Uncategorized

Will It Blast Through $125,000 Or Slip Back To $110,000?

VedVision HeadLines July 13, 2025
Bitcoin May Land On 36 More Company Balance Sheets This Year, Blockchain Firm Says
  • Uncategorized

Bitcoin May Land On 36 More Company Balance Sheets This Year, Blockchain Firm Says

VedVision HeadLines July 13, 2025

Recent Posts

  • The changing landscape of employment
  • US risks financial crisis ahead of midterm elections: former IMF official
  • Kate Middleton presents trophy to Jannik Sinner after he ended Carlos Alcaraz’s Wimbledon reign
  • Saina Nehwal announces separation from husband Parupalli Kashyap
  • Will It Blast Through $125,000 Or Slip Back To $110,000?

Recent Comments

No comments to show.

Archives

  • July 2025
  • June 2025
  • May 2025
  • April 2025

Categories

  • Current Affairs
  • Shopping
  • Uncategorized

You may have missed

The changing landscape of employment
  • Current Affairs

The changing landscape of employment

VedVision HeadLines July 13, 2025
US risks financial crisis ahead of midterm elections: former IMF official
  • Uncategorized

US risks financial crisis ahead of midterm elections: former IMF official

VedVision HeadLines July 13, 2025
Kate Middleton presents trophy to Jannik Sinner after he ended Carlos Alcaraz’s Wimbledon reign
  • Current Affairs

Kate Middleton presents trophy to Jannik Sinner after he ended Carlos Alcaraz’s Wimbledon reign

VedVision HeadLines July 13, 2025
Saina Nehwal announces separation from husband Parupalli Kashyap
  • Current Affairs

Saina Nehwal announces separation from husband Parupalli Kashyap

VedVision HeadLines July 13, 2025
Copyright © All rights reserved. | MoreNews by AF themes.