SentinelLabs has reported a new threat for macOS users from North Korean hackers employing the NimDoor virus to steal cryptocurrency wallet data.
How NimDoor Works
The new NimDoor virus is written in Nim, a programming language rarely used in malware. SentinelLabs noted that Apple's built-in protective mechanisms do not yet identify this virus, allowing it to infiltrate macOS devices without detection.
Attack Methods
Hackers use Telegram to contact targets, enticing them to download a fake Zoom update via Calendly. This update contains malicious code that installs without activating Apple's safety checks.
Security Recommendations
To protect against NimDoor, SentinelLabs recommends that cryptocurrency firms block unsigned installer packages, verify Zoom updates only from zoom.us, and audit Telegram contact lists for new profiles that may distribute executable files.
The warning from SentinelLabs highlights a growing threat from North Korean hackers who are employing diverse methods to steal data and funds from cryptocurrency companies.