North Korean Hackers Target Web3 with Nim Malware and Use ClickFix in BabyShark Campaign

North Korean-affiliated threat actors have been seen using malware created in the Nim programming language to attack Web3 and cryptocurrency-related organizations, highlighting a continuous change in their strategies.

In a post shared with The Hacker News, SentinelOne researchers Phil Stokes and Raffaele Sabato stated that the threat actors use a process injection technique and remote communications using wss, the TLS-encrypted version of the WebSocket protocol, which is unusual for macOS malware.

Utilizing SIGINT/SIGTERM signal handlers, a unique persistence mechanism installs persistence upon system reboot or malware termination.

The malware components are being tracked collectively by the cybersecurity firm under the name NimDoor. It’s important to note that, although the payloads used varied read more about North Korean Hackers Target Web3 with Nim Malware and Use ClickFix in BabyShark Campaign.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *