Listen to this Post

A Chilling New Cyber Threat Has Emerged
In a stunning development that sets a new precedent for cyberattacks on macOS, cybersecurity firm SentinelOne has uncovered a deeply sophisticated malware campaign named NimDoor, tied to the notorious North Korea-linked hacking collective Stardust Chollima (also known as TA444, APT38, or BlueNoroff). What makes this attack especially alarming is its stealthy use of the rarely seen Nim programming language on macOS, designed specifically to evade modern detection methods. The targets? High-value Web3, cryptocurrency firms, and fintech infrastructures across the globe.
Since April 2025, this campaign has exploited advanced social engineering on Telegram, fake Zoom SDK updates, covert data exfiltration, and resilient malware persistence tactics—all pointing to a new phase in the digital arms race. With process injection, TLS-encrypted WebSocket communications, and signal-handler-driven reinfections, NimDoor is setting a terrifying benchmark for future macOS threats. Here’s everything you need to know about this breakthrough in offensive cyber warfare.
MacOS Faces a NimDoor Breach: What You Should Know
The NimDoor malware marks a seismic shift in macOS cyber threats. Discovered by SentinelOne, this advanced malware campaign is attributed to the North Korean hacking group Stardust Chollima. NimDoor leverages binaries written in the Nim programming language, an unusual choice that allows the attackers to bypass traditional malware detection tools. First seen in April 2025, this malware specifically targets Web3, cryptocurrency firms, and blockchain startups, using advanced social engineering techniques mainly through Telegram.
The infection begins with attackers impersonating trusted contacts and inviting victims to schedule fake Zoom meetings via Calendly. A malicious AppleScript disguised as a Zoom SDK update is sent to the victim. The script contains a minor typo—“Zook” instead of “Zoom”—which helped researchers track it. Once executed, this script sets off a multi-stage infection process, delivering two Mach-O binaries: one written in C++ for initial payload execution and another in Nim for deeper system infiltration.
The malware uses TLS-encrypted WebSockets for secure communication with its command-and-control (C2) servers. Every 30 seconds, it transmits active process lists and accepts remote commands. A signal handler mechanism (SIGINT/SIGTERM) ensures persistence by reinstalling the malware if it is terminated or if the system reboots—a technique never before seen in macOS threats.
To expand its persistence, NimDoor drops fake LaunchAgents, “GoogIe LLC” and “CoreKitAgent,” further embedding itself in the system. Its data theft phase involves Bash scripts that extract credentials from MacOS Keychain, browser password vaults (including Chrome, Firefox, Safari, Brave, Arc, and Edge), and even Telegram’s internal databases—sources often storing crypto wallet keys and sensitive business credentials. The attackers use real Zoom meetings as a distraction, luring victims into a false sense of security during the breach.
Attribution points directly to Stardust Chollima, a North Korean APT group known for blending spear-phishing, deepfakes, and malware disguised as business tools. Their aim: stealing financial assets and evading international sanctions. NimDoor’s emergence is a wake-up call to cybersecurity professionals, especially in the crypto world, revealing that macOS is no longer the safe haven many believed it to be. Vigilance, threat-hunting, and cross-platform detection strategies are now essential in combating this new class of malware.
What Undercode Say:
The Rise of Language-Based Evasion
The decision to write part of NimDoor in Nim reflects a strategic move to outpace conventional malware analysis. Nim is rarely used in malware—especially on macOS—making it unfamiliar territory for both antivirus engines and forensic analysts. Much like Go and Rust (previously favored by North Korean hackers), Nim helps create binaries that are hard to reverse-engineer and often slip past static detection tools.
Social Engineering on a New Level
By combining Telegram impersonations, Calendly scheduling, and a fake Zoom SDK update, attackers demonstrate a level of social engineering sophistication far beyond typical phishing campaigns. This approach mimics real workflows of crypto professionals, making the deception incredibly convincing and difficult to avoid.
Real-Time Persistence: The Signal Handler Trap
The most chilling innovation is NimDoor’s signal handler persistence technique. Traditional malware might create startup items or services, but NimDoor’s method ensures that even if forcibly terminated, it silently reinstalls itself. This signals a shift toward self-healing malware, an emerging class of threats that actively resist remediation.
TLS-encrypted WebSockets: Hidden in Plain Sight
Using encrypted WebSockets (wss://) for C2 communications allows NimDoor to blend in with legitimate traffic, bypassing network-based anomaly detection systems. Every 30 seconds, the malware communicates with its operators, gathering live data, sending process information, and accepting dynamic payloads for execution.
A Multi-Layered Infection Chain
The layered structure of NimDoor—C++ loaders, Nim installers, hex-encoded AppleScript, and Bash-based exfiltration—ensures that even if one layer is detected or removed, others may still operate. It’s modular, resilient, and highly adaptable, embodying principles of modern offensive cyber operations.
LaunchAgent Spoofing and Persistence
Registering itself as “GoogIe LLC” (note the capital “I” in “Google”) and “CoreKitAgent,” NimDoor masks itself with plausible system-level names, tricking users and even some admins into ignoring them. These clever naming conventions help avoid casual detection and secure long-term persistence.
Focus on Crypto and Web3
This campaign shows that crypto organizations are now priority targets, not just for financial reasons but also because of their growing geopolitical significance. By stealing crypto wallet credentials and platform secrets, attackers aim to siphon funds, compromise user trust, and weaken the decentralized ecosystem from within.
Implications for macOS Security
Historically perceived as more secure than Windows, macOS is now clearly vulnerable to nation-state level threats. NimDoor shatters that illusion and forces Apple and security firms to prioritize cross-platform, signal-resilient defense mechanisms capable of detecting rare language threats and novel persistence tactics.
A Cyber Warfront Funded by Crypto Theft
Stardust Chollima, operating under North Korea’s military intelligence wing,
🔍 Fact Checker Results:
✅ NimDoor is confirmed to be written partially in Nim, an unusual choice on macOS
✅ Attribution to North Korea’s Stardust Chollima is supported by multiple threat intelligence sources
❌ There is no evidence the malware has yet spread beyond targeted crypto professionals
📊 Prediction:
Expect an uptick in macOS-targeted malware using niche programming languages like Nim and Rust.
The use of real-time C2 signaling and self-repairing malware will become more mainstream, forcing a shift in enterprise cybersecurity practices.
Crypto firms, especially those interacting over Telegram, are likely to face more deeply social-engineered attacks, with attackers mimicking real workflows and environments.
References:
Reported By: cyberpress.org
Extra Source Hub:
https://www.github.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




