Cybersecurity researchers have uncovered a sophisticated new macOS malware campaign dubbed “NimDoor,” believed to be orchestrated by North Korean hackers targeting Web3 and crypto startups. Disguised as a Zoom SDK update.
The malware is delivered through elaborate social engineering — beginning with fake Telegram messages and Calendly invites, followed by a malicious email link. Once launched, it exploits multiple scripting languages to install backdoors, steal data, and maintain long-term access.
According to SentinelLabs, NimDoor stands out for its technical complexity, using AppleScript, Bash, C++, and the rarely seen Nim programming language. It deploys process injection, encrypted WebSocket communications, and a unique persistence mechanism triggered on system shutdowns or restarts.
Sensitive information like Keychain credentials, browser data, and Telegram user data are exfiltrated through Bash scripts, highlighting a growing trend of advanced, cross-platform threats in the macOS ecosystem. The campaign underscores North Korea’s continued focus on the crypto industry as a high-value target.
Experts warn that these attacks reflect a broader evolution in threat actor tactics and advise startups in the sector to remain vigilant, avoid downloading unofficial updates, and implement robust endpoint security.
















