Close Menu
CrypThing
  • Directory
  • News
    • AI
    • Press Release
    • Altcoins
    • Memecoins
  • Analysis
  • Price Watch
  • Price Prediction
Facebook X (Twitter) Instagram Threads
CrypThingCrypThing
  • Directory
  • News
    • AI
    • Press Release
    • Altcoins
    • Memecoins
  • Analysis
  • Price Watch
  • Price Prediction
CrypThing
Home»Altcoins»North Korean hackers use fake Zoom updates to deliver ‘NimDoor’ macOS malware targeting crypto firms
Altcoins

North Korean hackers use fake Zoom updates to deliver ‘NimDoor’ macOS malware targeting crypto firms

adminBy adminJuly 26, 20252 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link Bluesky Reddit Telegram WhatsApp Threads
North Korean hackers use fake Zoom updates to deliver ‘NimDoor’ macOS malware targeting crypto firms
Share
Facebook Twitter Email Copy Link Bluesky Reddit Telegram WhatsApp

Reported by The BlockL SentinelLabs warns that North Korean groups use an unusual NimDoor macOS backdoor, hidden in fake Zoom updates, to steal cryptocurrency wallet data and passwords.

The threat follows a string of DPRK exploits that have extracted over $1.6 billion from cryptocurrency firms in the first half of 2025, according to TRM Labs.

A North Korean threat group is infecting Apple devices with a new computer virus called NimDoor to infiltrate cryptocurrency companies and steal wallet credentials, security firm SentinelLabs warned in a research report.

Attackers message targets on Telegram, a familiar social engineering tactic employed by cybercriminals. Hackers then organize a malicious meeting through Calendly and lure victims into downloading a bogus Zoom Update sideloaded with malware that runs without triggering Apple’s safety checks.

The implant stands out because it was written in Nim, a niche programming language rarely used in malware. SentinelLabs said Apple’s built-in protection signatures do not yet flag NimDoor, giving the backdoor a free pass onto macOS-powered machines. Once installed, it harvests browser passwords, Telegram databases, and crypto wallet files, then opens a login-item agent that reloads the malware and pulls follow-up payloads.

To address the issue, SentinelLabs urged crypto firms to block unsigned installer packages, verify Zoom updates only from zoom.us, and audit Telegram contact lists for new profiles that push executable files.

The warning adds to a growing DPRK playbook. Last week, Interchain Labs revealed Cosmos maintainers had unknowingly hired a North Korean developer, and U.S. prosecutors charged DPRK nationals with laundering more than $900,000 in stolen crypto via Tornado Cash. The U.S. Department of Justice says operatives posed as American citizens in several schemes to steal data from U.S. companies. TRM Labs estimates North Korea-linked groups siphoned $1.6 billion from web3 operators in the first half of 2025, led by February’s $1.5 billion Bybit breach. That’s over 70% of all crypto losses in H1, according to the security startup.

Crypto Deliver fake firms hackers Korean macOS malware NimDoor North targeting Updates Zoom
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link Bluesky WhatsApp Threads
Previous ArticleTron Flips ADA In Crypto Top 10, But Is This Sub $100M Market Cap Coin Remittix About To Flip Both In 2025?
Next Article Dogecoin Price Prediction Eyes Breakout Toward $0.36 As Bullish Momentum Grows
admin

Related Posts

NVIDIA cuTile Python Guide Shows 90% cuBLAS Performance for Matrix Ops

January 15, 2026

NVIDIA cuOpt Solver Cracks Four Previously Unsolved Optimization Problems

January 13, 2026

Story Protocol’s IP token surges 22%, outpacing top altcoins: check forecast

January 12, 2026
Trending News

10 Best Altcoin Prop Trading Firms 2025

November 19, 2025

$3.4 million Bitcoin? Arthur Hayes thinks it's coming

September 24, 2025

AAVE Price Prediction: Breaking $340 Resistance Could Drive AAVE to $385 by October 2025

September 2, 2025

Peter Thiel-backed exchange Bullish targets $4.2 billion valuation, plans to convert IPO proceeds into stablecoins

August 4, 2025
About Us

At crypthing, we’re passionate about making the crypto world easier to (under)stand- and we believe everyone should feel welcome while doing it. Whether you're an experienced trader, a blockchain developer, or just getting started, we're here to share clear, reliable, and up-to-date information to help you grow.

Don't Miss

Reporters found that Zerebro founder was alive and inhaling his mother and father’ home, confirming that the suicide was staged

May 9, 2025

Openai launches initiatives to spread democratic AI through global partnerships

May 9, 2025

Stripe announces AI Foundation model for payments and introduces deeper Stablecoin integration

May 9, 2025
Top Posts

10 Best Altcoin Prop Trading Firms 2025

November 19, 2025

$3.4 million Bitcoin? Arthur Hayes thinks it's coming

September 24, 2025

AAVE Price Prediction: Breaking $340 Resistance Could Drive AAVE to $385 by October 2025

September 2, 2025
  • About Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
© 2026 crypthing. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.