NimDoor MacOS Malware
2025-07-14 • Poly Swarm •
North Korea-linked operators, assessed in the excerpt as likely Stardust Chollima, used NimDoor macOS malware against Web3 and cryptocurrency organizations. The intrusion chain began with Telegram social engineering and fake Zoom meeting lures, then delivered a malicious AppleScript posing as a Zoom SDK update. Nim and C++ Mach-O binaries, LaunchAgent persistence, process injection, TLS-encrypted WebSocket C2, and signal-handler based reinstallation supported backdoor access and stealth. The malware stole Keychain credentials, browser data, Telegram databases, process lists, and other sensitive information, showing continued DPRK interest in macOS endpoints inside the crypto sector.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ea8a58bbb6d5614855a470b2d363019… | 2025-07-14 | 2025-07-14 |
| HASH | e6a7c54c01227adcb2a180e62f0082d… | 2025-07-14 | 2025-07-14 |
| HASH | bcef50a375c8b4edbe7c80e220c1bb5… | 2025-07-14 | 2025-07-14 |
| HASH | 74cbec210ba601caeb063d44e510fc0… | 2025-07-14 | 2025-07-14 |
| HASH | 0d1e3a9e6f3211b7e3072d736e9a2e6… | 2025-07-14 | 2025-07-14 |
| HASH | 9c48e2a01d852e08f923a4638ef391b… | 2025-07-14 | 2025-07-14 |
| HASH | 69a012ff46565169534ccefb175f87b… | 2025-07-14 | 2025-07-14 |
| HASH | 64c9347d794243be26e811b5eb90fb1… | 2025-07-14 | 2025-07-14 |
| HASH | 7ffc83877389ebb86d201749d73b5e3… | 2025-07-14 | 2025-07-14 |
| HASH | 41660a23e5db77597994e17f9f773d0… | 2025-04-23 | 2025-07-14 |
| HASH | 469fd8a280e89a6edd0d704d0be4c7e… | 2025-04-23 | 2025-07-14 |