Close Menu
  • Home
  • Art News
  • Cinema
  • Antiques
  • Jewellery
  • Crypto News
Facebook X (Twitter) Instagram
  • Home
  • Art News
  • Cinema
  • Antiques
  • Jewellery
  • Crypto News
Facebook X (Twitter) Instagram Pinterest YouTube
AMG
  • Home
  • Art News
  • Cinema
  • Antiques
  • Jewellery
  • Crypto News
AMG
Home » North Korean Hackers Unleash New Apple Malware in Imminent Crypto Threat—Here’s How
North Korean Hackers Unleash New Apple Malware in Imminent Crypto Threat—Here’s How

North Korean Hackers Unleash New Apple Malware in Imminent Crypto Threat—Here’s How

July 3, 2025No Comments4 Mins Read Crypto News
Share
Facebook Twitter LinkedIn Pinterest Email

North Korea-linked threat actors have launched NimDoor to target companies in the Web3 and crypto industry. NimDoor, a sophisticated malware compiled in the Nim programming language specifically targets macOS systems.

Unlike more widely used programming languages, Nim allows code execution during compilation, creating binaries that mix runtime and malware logic. This complicates reverse engineering and detection efforts.

According to a new report by SentinelLabs, the campaign was first observed in April 2025 during an attack on a crypto startup. Multiple security firms have since confirmed similar incidents affecting other companies in the space.

How North Korea Deploys Cyberattacks on Crypto Startups: SentinelLabs Report

SentinelLabs reported that the attackers use classic social engineering techniques to trick victims into running the malicious code.

Victims are approached on Telegram by impersonated contacts and invited to schedule a meeting via Calendly. They later receive an email with a Zoom link and instructions to install a supposed “Zoom SDK update.”

According to the report, the link directs users to an AppleScript file hosted on domains mimicking Zoom’s official URLs. The script is heavily padded with thousands of lines of whitespace and ends with code that fetches a second-stage payload from attacker-controlled servers.

After the initial download, the malware deploys two Mach-O binaries in the system’s temporary directory. The first binary, written in C++, performs process injection to launch a trojan.

The second binary, compiled from Nim and labeled installer, installs persistence tools that ensure the malware remains active even after a system reboot or termination.

This stage drops two more Nim-based binaries: GoogIe LLC and CoreKitAgent, both of which play roles in long-term access and system monitoring. Once deployed, the malware executes two that steal user data.

The upl script extracts login credentials and browsing history from browsers such as Google Chrome and Firefox. The tlgrm script specifically targets Telegram data. All stolen data is compressed and sent to servers disguised as secure upload portals hosted by the attackers.

North Korea’s Cyber Arsenal Evolves: Hackers Turn to Rare Programming Language

SentinelLabs notes that this isn’t the first time DPRK-affiliated actors have used less common programming languages. Past campaigns have involved Go and Rust, and more recently, Crystal.

Analysts believe the use of such languages will rise as attackers look for ways to evade traditional detection tools.

This recent cybersecurity threat adds to the growing list of such activities emanating from North Korea. In April, North Korean hackers targeted U.S. crypto developers through a malware campaign using fake companies, including Blocknovas LLC and Softglide LLC, registered with false addresses.

North Korean cyber spies reportedly set up fake US firms to deploy malware targeting crypto developers, violating Treasury sanctions.#NorthKorea #CyberSecurity https://t.co/TvCmrspaep

— Cryptonews.com (@cryptonews) April 25, 2025

Tied to a Lazarus Group subgroup, the operation used fake job offers to spread malware stealing crypto wallets and credentials.

In May, South Korea and the EU pledged closer cooperation to combat cyber threats, focusing on North Korea’s crypto crimes. During talks in Seoul, officials stressed the need for joint action amid rising attacks.

Lawmaker Ha Tae-keung stated that North Korean hackers have stolen another $310 million in cryptocurrency from South Korean wallets since the $2 billion thefts reported by the UN in 2019. Chainalysis, in addition, reported $1.3 billion in stolen funds in 2024

💰 Crypto hackers from North Korea stole $1.3 billion in funds in 2024, new data released this week from Chainalysis shows.#NorthKorea #CryptoHackershttps://t.co/TQYgKiaQ22

— Cryptonews.com (@cryptonews) December 20, 2024

Just two days ago, the U.S. DOJ charged four North Koreans with stealing over $900,000 in cryptocurrency by posing as remote IT workers at blockchain firms. Using fake identities, they altered smart contracts to carry out the thefts, part of a scheme to fund North Korea’s weapons program.

The post North Korean Hackers Unleash New Apple Malware in Imminent Crypto Threat—Here’s How appeared first on Cryptonews.


Credit: Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Bitcoin, Ethereum, XRP Price Prediction for Next Week (28th July

July 27, 2025

Are Whales Signaling the Next XRP Rally With 130M Tokens Bought in 24 Hours?

July 26, 2025

Weekly Crypto Roundup: Ripple CEO Selling Erodes Trust While Unilabs (UNIL) Leads July Demand

July 26, 2025

Algorand Price Prediction 2025, 2026, 2027

July 26, 2025
Add A Comment

Comments are closed.

Editors Picks

Bitcoin, Ethereum, XRP Price Prediction for Next Week (28th July

July 27, 2025

Should Fine Artists Embrace Digital Art or Fear It? The Untold Revolutionary Benefit

July 26, 2025

Are Whales Signaling the Next XRP Rally With 130M Tokens Bought in 24 Hours?

July 26, 2025

Weekly Crypto Roundup: Ripple CEO Selling Erodes Trust While Unilabs (UNIL) Leads July Demand

July 26, 2025
About

Angelamaingallery is an online news portal that aims to share the latest Art news, Antiques, Jewellery, Cinema, Crypto
and much more stuff.

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Art in America’s “New Talent” Issue Features 20 Artists to Watch

May 13, 2025

How Blockchain Technology is Transforming Online Gambling in 2025

June 5, 2025

Have Solana & TRON Whales Had Inside Info On New Meme Coin Launch Expected To Hit 10,000% Gains? There Is Still Time!

February 6, 2025
Facebook X (Twitter) Instagram Pinterest YouTube
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$77,791.000.27%
  • ethereumEthereum(ETH)$2,320.790.46%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.440.67%
  • binancecoinBNB(BNB)$637.780.51%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$86.661.49%
  • tronTRON(TRX)$0.322135-1.79%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.55%
  • dogecoinDogecoin(DOGE)$0.0985441.31%
  • whitebitWhiteBIT Coin(WBT)$55.030.25%
  • USDSUSDS(USDS)$1.000.00%
  • HyperliquidHyperliquid(HYPE)$41.662.21%
  • leo-tokenLEO Token(LEO)$10.24-0.42%
  • cardanoCardano(ADA)$0.2531441.69%
  • bitcoin-cashBitcoin Cash(BCH)$454.87-0.10%
  • moneroMonero(XMR)$373.83-1.62%
  • chainlinkChainlink(LINK)$9.431.71%
  • zcashZcash(ZEC)$356.353.64%
  • CantonCanton(CC)$0.151607-0.55%
  • stellarStellar(XLM)$0.173456-0.56%
  • MemeCoreMemeCore(M)$4.28-8.52%
  • daiDai(DAI)$1.000.00%
  • USD1USD1(USD1)$1.000.01%
  • litecoinLitecoin(LTC)$56.540.80%
  • avalanche-2Avalanche(AVAX)$9.481.38%
  • hedera-hashgraphHedera(HBAR)$0.0918991.64%
  • Ethena USDeEthena USDe(USDE)$1.000.01%
  • suiSui(SUI)$0.951.27%
  • shiba-inuShiba Inu(SHIB)$0.0000061.62%
  • RainRain(RAIN)$0.0075301.44%
  • paypal-usdPayPal USD(PYUSD)$1.000.00%
  • the-open-networkToncoin(TON)$1.343.27%
  • crypto-com-chainCronos(CRO)$0.0704351.31%
  • Circle USYCCircle USYC(USYC)$1.12-0.03%
  • tether-goldTether Gold(XAUT)$4,698.800.57%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.076328-0.21%
  • BittensorBittensor(TAO)$251.162.64%
  • Global DollarGlobal Dollar(USDG)$1.00-0.02%
  • pax-goldPAX Gold(PAXG)$4,702.770.62%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • polkadotPolkadot(DOT)$1.272.64%
  • mantleMantle(MNT)$0.650.51%
  • uniswapUniswap(UNI)$3.270.82%
  • SkySky(SKY)$0.0842070.41%
  • nearNEAR Protocol(NEAR)$1.410.46%
  • Falcon USDFalcon USD(USDF)$1.000.01%
  • okbOKB(OKB)$84.621.14%
  • Pi NetworkPi Network(PI)$0.1712560.99%
  • HTX DAOHTX DAO(HTX)$0.000002-1.01%
  • AsterAster(ASTER)$0.67-0.61%
  • pepePepe(PEPE)$0.0000042.09%
  • Ripple USDRipple USD(RLUSD)$1.000.02%
  • aaveAave(AAVE)$95.822.55%
  • Janus Henderson Anemoy Treasury FundJanus Henderson Anemoy Treasury Fund(JTRSY)$1.100.00%
  • usddUSDD(USDD)$1.000.01%
  • bitget-tokenBitget Token(BGB)$1.98-0.27%
  • internet-computerInternet Computer(ICP)$2.480.75%
  • ethereum-classicEthereum Classic(ETC)$8.560.92%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.130.31%
  • BFUSDBFUSD(BFUSD)$1.000.00%
  • OndoOndo(ONDO)$0.2636901.20%
  • kucoin-sharesKuCoin(KCS)$8.460.25%
  • gatechain-tokenGate(GT)$7.38-0.08%
  • MorphoMorpho(MORPHO)$1.84-1.10%
  • Pump.funPump.fun(PUMP)$0.001768-1.13%
  • quant-networkQuant(QNT)$71.500.33%
  • algorandAlgorand(ALGO)$0.1162358.99%
  • Spiko EU T-Bills Money Market FundSpiko EU T-Bills Money Market Fund(EUTBL)$1.230.30%
  • cosmosCosmos Hub(ATOM)$2.044.79%
  • United StablesUnited Stables(U)$1.000.00%
  • Superstate Short Duration U.S. Government Securities Fund (USTB)Superstate Short Duration U.S. Government Securities Fund (USTB)(USTB)$11.060.01%
  • polygon-ecosystem-tokenPOL (ex-MATIC)(POL)$0.093345-1.10%
  • EthenaEthena(ENA)$0.1099892.07%
  • render-tokenRender(RENDER)$1.821.23%
  • kaspaKaspa(KAS)$0.033584-1.45%
  • nexoNEXO(NEXO)$0.910.89%
  • worldcoin-wldWorldcoin(WLD)$0.2625310.72%
  • arbitrumArbitrum(ARB)$0.1316362.61%
  • aptosAptos(APT)$0.983.03%
  • Blockchain CapitalBlockchain Capital(BCAP)$82.760.00%
  • filecoinFilecoin(FIL)$0.952.33%
  • ​​Stable​​Stable(STABLE)$0.032111-6.93%
  • Official TrumpOfficial Trump(TRUMP)$2.963.49%
  • justJUST(JST)$0.080571-1.07%
  • flare-networksFlare(FLR)$0.0079330.22%
  • vechainVeChain(VET)$0.0074502.32%
  • dexeDeXe(DEXE)$13.635.32%
  • beldexBeldex(BDX)$0.0803110.21%
  • JupiterJupiter(JUP)$0.1743030.76%
  • MidnightMidnight(NIGHT)$0.036752-0.54%
  • xdce-crowd-saleXDC Network(XDC)$0.0302430.27%
  • Provenance BlockchainProvenance Blockchain(HASH)$0.0104872.55%
  • OUSGOUSG(OUSG)$115.030.01%
  • USDtbUSDtb(USDTB)$1.000.04%
  • GHOGHO(GHO)$1.000.02%
  • bonkBonk(BONK)$0.000006-0.18%
  • Usual USDUsual USD(USD0)$1.000.00%
  • Pudgy PenguinsPudgy Penguins(PENGU)$0.0086172.20%
  • YLDSYLDS(YLDS)$1.00-0.01%