macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware

2025-07-02 Sentinel One

https://www.sentinelone.com/labs/macos-nimdoor-dprk-threat-actors-target-web3-and-crypto-platforms-with-nim-based-malware/

Thumbnail for macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware

SentinelLABS analyzed NimDoor, a DPRK-linked macOS malware campaign targeting Web3 and cryptocurrency businesses through social engineering and fake Zoom update lures. The infection chain uses AppleScript, C++, Bash, and Nim-compiled Mach-O binaries, with Telegram impersonation, Calendly meeting pretexts, and attacker domains resembling legitimate Zoom infrastructure. The malware shows unusual macOS tradecraft, including process injection into a suspended process, WebSocket-over-TLS command-and-control, encrypted configuration handling, and signal-handler-based persistence. Follow-on scripts collect Keychain, browser, Telegram, and system data from staging paths such as ~/Library/DnsService, making the campaign significant for crypto organizations that rely on macOS developer workstations.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://dataupload.store/upload… 2025-07-02 2025-10-28
DOMAIN dataupload.store 2025-04-23 2025-10-28
HASH 1e76f497051829fa804e72b9d14f44d… 2025-07-02 2025-07-02
HASH 945fcd3e08854a081c04c06eeb95ad6… 2025-07-02 2025-07-02
HASH e227e2e4a6ffb7280dfe7618be20514… 2025-07-02 2025-07-02
HASH 7c04225a62b953e1268653f637b569a… 2025-07-02 2025-07-02
HASH 027d4020f2dd1eb473636bc112a84f0… 2025-07-02 2025-07-02
HASH 1a5392102d57e9ea4dd33d3b7181d66… 2025-07-02 2025-07-02
HASH 2d746dda85805c79b5f6ea376f97d9b… 2025-07-02 2025-07-02
HASH 023a15ac687e2d2e187d03e9976a89e… 2025-07-02 2025-07-02
HASH 2ed2edec8ccc44292410042c730c190… 2025-07-02 2025-07-02
HASH 3168e996cb20bd7b4208d0864e962a4… 2025-07-02 2025-07-02
HASH 4743d5202dbe565721d75f7fb1eca43… 2025-07-02 2025-07-02
HASH 2c0177b302c4643c49dd7016530a474… 2025-07-02 2025-07-02
HASH a25c06e8545666d6d2a88c8da300cf3… 2025-07-02 2025-07-02
HASH 06566eabf54caafe36ebe94430d392b… 2025-07-02 2025-07-02
HASH bb72ca0e19a95c48a9ee4fd658958a0… 2025-07-02 2025-07-02
HASH 0602a5b8f089f957eeda51f81ac0f9a… 2025-07-02 2025-07-02
HASH ee3795f6418fc0cacbe884a8eb80349… 2025-07-02 2025-07-02
HASH 5b16e9d6e92be2124ba496bf82d38fb… 2025-07-02 2025-07-02
HASH c9540dee9bdb28894332c5a74f696b4… 2025-07-02 2025-07-02
HASH 16a6b0023ba3fde15bd0bba1b17a18b… 2025-07-02 2025-07-02
HASH 08af4c21cd0a165695c756b6fda3701… 2025-07-02 2025-07-02
HASH 79f37e0b728de2c5a4bfe8fcf292941… 2025-07-02 2025-07-02

Related Reports

« Back