• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

How NimDoor Attacks macOS Devices: Insights from SentinelLabs

user avatar

by Giorgi Kostiuk

8 hours ago


SentinelLabs has revealed a new cyber threat targeting macOS devices, originating from North Korean hackers. The attack, dubbed NimDoor, employs the Nim programming language for complex hacking methods.

How the Attack is Executed

According to SentinelLabs' report, the NimDoor attack begins by impersonating a trusted contact, leading to a meeting scheduled via Calendly. The victim receives an email suggesting an update for Zoom, which contains a script with malicious code that downloads two macOS binaries and initiates two independent execution chains. The first chain gathers general system information, while the second ensures long-term access for the attacker.

The attack continues with the installation of two Bash scripts, one collecting information from popular browsers, and the other extracting encrypted data from Telegram, which is then sent to a controlled server.

Financial Flows

ZachXBT, a known blockchain investigator, has uncovered substantial financial transfers to DPRK developers working on various projects. Since the start of the year, approximately $2.76 million in equivalent USDC has been sent to addresses linked to these workers. Some of these addresses may be associated with a suspected individual blacklisted by Tether in 2023. Zach cautions that the presence of North Korean IT workers may indicate potential risks for startups.

Conclusion

The NimDoor attack highlights the growing threats to macOS devices, particularly in the context of Web3 and crypto projects. The complexity of the attacking methodologies and related financial flows make this situation significant for user safety. Experts urge attention to potential vulnerabilities associated with hiring workers from North Korea.

In conclusion, the new research from SentinelLabs sheds light on the intricate and dangerous attacks that could threaten the security of businesses and users in today's digital ecosystem.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

Other news

Dogecoin Shows Worst Performance Among Top 10 Cryptos

chest

Dogecoin records significant losses among crypto assets, drawing attention to investor uncertainty and restricted price movement.

user avatarGiorgi Kostiuk

Bitget Adds Token Cross to Its GameFi Zone

chest

Trading for the Cross token begins on July 4, 2025. This move reflects the growing popularity of GameFi.

user avatarGiorgi Kostiuk

Y4Trade Introduces Trading Platform with Funding Opportunities

chest

Y4Trade launches its trading platform offering over 200 currencies and a unique academy for traders.

user avatarGiorgi Kostiuk

Amber International Raises $25.5M for Expanding Crypto Services

chest

Amber International has raised $25.5 million to support its cryptocurrency reserve strategy and expand in the U.S. and Southeast Asia.

user avatarGiorgi Kostiuk

Crypto Innovations in Africa: The Need for a Change in Approach

chest

Exploring why Africa needs respect and collaboration rather than new cryptocurrencies.

user avatarGiorgi Kostiuk

Arthur Hayes: $5 Trillion U.S. Debt May Lead to Financial Instability

chest

Arthur Hayes expresses concerns about rising U.S. national debt and insufficient bond market buyers.

user avatarGiorgi Kostiuk
dapp expert logo
© 2020-2025. DappExpert. All rights reserved.
© 2020-2025. DappExpert. All rights reserved.

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.