Stand Up for Investors' Right to Know – Say No to Dumping Sell-Offs! [RootData Bounty Campaign]
API Download the RootData App

North Korean hackers use Nim to write malware targeting MAC devices, specifically focusing on cryptocurrency wallets and Telegram data

Jul 03, 2025 14:35:00

Share to

ChainCatcher news, according to a report released by cybersecurity company Sentinel Labs on Wednesday, North Korean hackers are using a new type of malware targeting Apple devices to attack cryptocurrency companies. The hackers impersonate trusted individuals on instant messaging applications like Telegram, sending fake Zoom update files that actually install malware named "NimDoor."

This malware is written in the rare Nim programming language, which can bypass Apple's memory protection mechanisms and deploy information stealers specifically targeting cryptocurrency wallets and browser passwords. The Nim language is becoming a new favorite among cybercriminals because it can run on Windows, Mac, and Linux without modification, compiles quickly, and is difficult to detect.

The malware also includes scripts capable of stealing the encrypted local database and decryption keys from Telegram, and it waits for 10 minutes before activation to evade security scans.

Related Projects

Latest News

Data: BTC fell below 88,000 USD

ChainCatcher

Jan 01, 2026 20:58:22

Data: BTC falls below 88,000 USD

ChainCatcher

Jan 01, 2026 12:18:18

Data: BTC breaks through 88000 USD

ChainCatcher

Jan 01, 2026 09:14:01

Data: ETH falls below 3000 USD

ChainCatcher

Dec 31, 2025 22:54:18

Data: ETH breaks 3000 USD

ChainCatcher

Dec 31, 2025 21:54:18

Recent Fundraising

More
$50M Dec 30, 2025
-- Dec 26, 2025
$1M Dec 25, 2025

New Tokens

More
Dec 24, 2025
Dec 23, 2025
Dec 20, 2025

Latest Updates on 𝕏

More
Dec 28, 2025
Dec 27, 2025
Dec 27, 2025