NimDoor MacOS Malware

2025-07-14 Poly Swarm

https://blog.polyswarm.io/nimdoor-macos-malware

Thumbnail for NimDoor MacOS Malware

North Korea-linked operators, assessed in the excerpt as likely Stardust Chollima, used NimDoor macOS malware against Web3 and cryptocurrency organizations. The intrusion chain began with Telegram social engineering and fake Zoom meeting lures, then delivered a malicious AppleScript posing as a Zoom SDK update. Nim and C++ Mach-O binaries, LaunchAgent persistence, process injection, TLS-encrypted WebSocket C2, and signal-handler based reinstallation supported backdoor access and stealth. The malware stole Keychain credentials, browser data, Telegram databases, process lists, and other sensitive information, showing continued DPRK interest in macOS endpoints inside the crypto sector.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ea8a58bbb6d5614855a470b2d363019… 2025-07-14 2025-07-14
HASH e6a7c54c01227adcb2a180e62f0082d… 2025-07-14 2025-07-14
HASH bcef50a375c8b4edbe7c80e220c1bb5… 2025-07-14 2025-07-14
HASH 74cbec210ba601caeb063d44e510fc0… 2025-07-14 2025-07-14
HASH 0d1e3a9e6f3211b7e3072d736e9a2e6… 2025-07-14 2025-07-14
HASH 9c48e2a01d852e08f923a4638ef391b… 2025-07-14 2025-07-14
HASH 69a012ff46565169534ccefb175f87b… 2025-07-14 2025-07-14
HASH 64c9347d794243be26e811b5eb90fb1… 2025-07-14 2025-07-14
HASH 7ffc83877389ebb86d201749d73b5e3… 2025-07-14 2025-07-14
HASH 41660a23e5db77597994e17f9f773d0… 2025-04-23 2025-07-14
HASH 469fd8a280e89a6edd0d704d0be4c7e… 2025-04-23 2025-07-14

Related Actors

Related Reports

« Back