Tag: NimDoor crypto-theft

NimDoor crypto-theft macOS malware revives itself when killed
News

NimDoor crypto-theft macOS malware revives itself when killed

A new type of macOS malware known as NimDoor has been used by North Korean state-sponsored hackers in a campaign against web3 and bitcoin firms. After examining the payloads, researchers found that the attacker used novel tactics and a signal-based persistence method that had never been observed before. The attack chain is similar to that of the Huntress managed security platform that was recently connected to BlueNoroff. It entails reaching out to victims over Telegram and tricking them into installing a phony Zoom SDK update that is sent to them via email and Calendly. The threat actor employed C++ and Nim-compiled binaries (together tracked as NimDoor) on macOS, according to a report released today by researchers at cybersecurity firm SentinelOne this is a more unusual choice ...