North Korean hackers use fake Zoom update to spread macOS malware 'NimDoor' targeting crypto firms

2025/07/03 17:57

PANews reported on July 3 that according to The Block, cybersecurity company SentinelLabs recently discovered that North Korean hacker groups used a new "NimDoor" macOS backdoor program to attack cryptocurrency companies. The malware spreads through fake Zoom update packages and can steal browser passwords, Telegram data, and encrypted wallet files. The attacker first contacts the target on Telegram, arranges a meeting through Calendly, and induces the victim to download the infected "Zoom update." The backdoor is written in the unpopular programming language Nim and can bypass Apple's security detection. Once installed, a login item will be automatically created to run continuously and download subsequent attack modules. Security experts recommend that cryptocurrency companies take three protective measures: block unsigned installation packages, download updates only from the zoom.us domain name, and review the Telegram contact list.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.