Close Menu
CrypThing
  • Directory
  • Slot
  • News
    • AI
    • Press Release
    • Altcoins
    • Memecoins
  • Analysis
  • Price Watch
  • Price Prediction
Facebook X (Twitter) Instagram Threads
CrypThingCrypThing
  • Directory
  • Slot
  • News
    • AI
    • Press Release
    • Altcoins
    • Memecoins
  • Analysis
  • Price Watch
  • Price Prediction
CrypThing
Home»Altcoins»North Korean hackers use fake Zoom updates to deliver ‘NimDoor’ macOS malware targeting crypto firms
Altcoins

North Korean hackers use fake Zoom updates to deliver ‘NimDoor’ macOS malware targeting crypto firms

adminBy adminJuly 26, 20252 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link Bluesky Reddit Telegram WhatsApp Threads
North Korean hackers use fake Zoom updates to deliver ‘NimDoor’ macOS malware targeting crypto firms
Share
Facebook Twitter Email Copy Link Bluesky Reddit Telegram WhatsApp

Reported by The BlockL SentinelLabs warns that North Korean groups use an unusual NimDoor macOS backdoor, hidden in fake Zoom updates, to steal cryptocurrency wallet data and passwords.

The threat follows a string of DPRK exploits that have extracted over $1.6 billion from cryptocurrency firms in the first half of 2025, according to TRM Labs.

A North Korean threat group is infecting Apple devices with a new computer virus called NimDoor to infiltrate cryptocurrency companies and steal wallet credentials, security firm SentinelLabs warned in a research report.

Attackers message targets on Telegram, a familiar social engineering tactic employed by cybercriminals. Hackers then organize a malicious meeting through Calendly and lure victims into downloading a bogus Zoom Update sideloaded with malware that runs without triggering Apple’s safety checks.

The implant stands out because it was written in Nim, a niche programming language rarely used in malware. SentinelLabs said Apple’s built-in protection signatures do not yet flag NimDoor, giving the backdoor a free pass onto macOS-powered machines. Once installed, it harvests browser passwords, Telegram databases, and crypto wallet files, then opens a login-item agent that reloads the malware and pulls follow-up payloads.

To address the issue, SentinelLabs urged crypto firms to block unsigned installer packages, verify Zoom updates only from zoom.us, and audit Telegram contact lists for new profiles that push executable files.

The warning adds to a growing DPRK playbook. Last week, Interchain Labs revealed Cosmos maintainers had unknowingly hired a North Korean developer, and U.S. prosecutors charged DPRK nationals with laundering more than $900,000 in stolen crypto via Tornado Cash. The U.S. Department of Justice says operatives posed as American citizens in several schemes to steal data from U.S. companies. TRM Labs estimates North Korea-linked groups siphoned $1.6 billion from web3 operators in the first half of 2025, led by February’s $1.5 billion Bybit breach. That’s over 70% of all crypto losses in H1, according to the security startup.

Crypto Deliver fake firms hackers Korean macOS malware NimDoor North targeting Updates Zoom
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link Bluesky WhatsApp Threads
Previous ArticleTron Flips ADA In Crypto Top 10, But Is This Sub $100M Market Cap Coin Remittix About To Flip Both In 2025?
Next Article Dogecoin Price Prediction Eyes Breakout Toward $0.36 As Bullish Momentum Grows
admin

Related Posts

Plume price forecast: SEC transfer agent nod boosts bulls

October 7, 2025

Institutional Integration of Digital Assets Surges Amid $4 Trillion Ecosystem

October 6, 2025

Crypto BEAR TRAP Set, Last Accumulation Before LIFTOFF for Altcoin Market

October 6, 2025
Trending News

The last call before the lift off? Dogecoin coil for important breakouts

October 3, 2025

How To Use A Bitcoin Heatmap For Smarter Trading Decisions

October 2, 2025

SK Planet Acquires MOCA Coin for Decentralized Identity Integration

October 2, 2025

Horizen (ZEN) gains 12% to break above $7

October 1, 2025
About Us

At crypthing, we’re passionate about making the crypto world easier to (under)stand- and we believe everyone should feel welcome while doing it. Whether you're an experienced trader, a blockchain developer, or just getting started, we're here to share clear, reliable, and up-to-date information to help you grow.

Don't Miss

Reporters found that Zerebro founder was alive and inhaling his mother and father’ home, confirming that the suicide was staged

May 9, 2025

Openai launches initiatives to spread democratic AI through global partnerships

May 9, 2025

Stripe announces AI Foundation model for payments and introduces deeper Stablecoin integration

May 9, 2025
Top Posts

The last call before the lift off? Dogecoin coil for important breakouts

October 3, 2025

How To Use A Bitcoin Heatmap For Smarter Trading Decisions

October 2, 2025

SK Planet Acquires MOCA Coin for Decentralized Identity Integration

October 2, 2025
  • About Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
© 2025 crypthing. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.