North Korea's 'NimDoor' Malware Exposes Crypto Firms to New macOS Threat
North Korea's NimDoor malware targets macOS users in the crypto sector with fake Zoom updates and social engineering tactics.
A new cybersecurity threat targeting macOS users has emerged, and it’s coming from one of the most notorious state-sponsored hacking regimes: North Korea. The latest campaign involves a sophisticated malware strain dubbed "NimDoor," engineered to breach systems belonging to cryptocurrency and Web3 firms by masquerading as a legitimate Zoom update.
Initially detected in January 2025, NimDoor represents a major evolution in North Korea’s cyber toolkit. This malware leverages the Nim programming language and AppleScript to infiltrate Apple’s operating system, utilizing modular components like CoreKitAgent and the falsely named "Google LLC" to ensure stealth and persistence. Its signal-based persistence technique allows it to remain active even after system reboots, making it particularly resilient.
The infection vector is social engineering. Hackers distribute the malware through spear-phishing emails that imitate legitimate sources, such as respected business publications or national security officials. These emails coax victims into downloading malicious RAR archives or interacting with fake PDF attachments. Once executed, these payloads not only steal system information but also schedule automated tasks to maintain access.
One variant of the attack, dubbed "ClickFix," involves guiding users to open the Windows Run dialogue and execute PowerShell commands. In some cases, fake job listings on spoofed employment websites trigger pop-ups prompting users to install Chrome Remote Desktop, thereby handing over full system access to the attackers.
The focus on crypto and Web3 targets reflects North Korea’s ongoing efforts to fund its regime through cybercrime, particularly in light of global sanctions. This was made brutally clear in February 2025, when the TraderTraitor group was linked to a $1.5 billion theft from the crypto exchange Bybit.
NimDoor’s focus on macOS is especially alarming given the common assumption that Apple’s ecosystem is less vulnerable to malware. This campaign upends that belief, exposing critical weaknesses and the urgent need for better defensive protocols.
Cybersecurity experts urge organizations to respond proactively. Key recommendations include training staff to detect phishing attempts, enforcing multi-factor authentication, and monitoring systems for unauthorized remote access tools. Regular software updates and vetting of third-party services are also critical to bolstering defenses.
As North Korean hackers adapt their methods, the NimDoor campaign serves as a stark reminder: No platform is immune. In the evolving landscape of cyber warfare, constant vigilance and robust digital hygiene are essential.



