With NimDoor, Mac OS isn’t safe anymore!

nimdoor malware mac os

North Korean hackers are using new types of harmful software (malware) to attack Apple devices. They are doing this as part of a plan to steal from cryptocurrency companies.

A report from cybersecurity company Sentinel Labs on Wednesday said the hackers pretend to be a trusted person on messaging apps like Telegram. Then, they ask for a fake Zoom meeting using a Google Meet link. After that, they send a file that looks like a Zoom update, but it’s actually malware.

How does it work?

When the fake “update” is opened, it puts malware called “NimDoor” onto Mac computers. This malware tries to steal things like crypto wallets and saved passwords from web browsers.

In the past, many people thought Mac computers were safer from hackers, but that’s not true.

Even though the way the hackers trick people is common, this malware is written in a rare coding language called Nim. This makes it harder for security programs to find and stop it.

What is Nim?

Nim is a new and not very common programming language. Hackers like it because they can use it to create malware that works on Windows, Mac, and Linux without making changes. This means they can write one program and attack many types of computers.

Nim is also fast at turning code into working programs. It creates files that can run on their own, and it’s harder for security tools to catch it.

The harmful file (called a payload) includes a tool that secretly steals saved information from browsers and the computer system. It packs this data and sends it out to the hackers without the user knowing.

There is also a special script that steals Telegram’s local database and the keys needed to unlock it.

The malware is smart, it waits ten minutes before starting, so security programs are less likely to notice it.

In June, cybersecurity company Huntress said malware like this was connected to BlueNoroff, a hacking group backed by North Korea.

DISCLAIMER AND RISK WARNING

The content published on Coin Medium is intended solely for informational and educational purposes. It should not be interpreted as financial, investment, legal, or other professional advice. While we strive to ensure accuracy, readers are strongly encouraged to conduct their own research and consult with a qualified professional before making any financial decisions. Coin Medium is not responsible for any losses or damages resulting from reliance on any content, products, or services mentioned in our articles or content belonging to the Coin Medium brand, including but not limited to its social media, newsletters, or posts related to Coin Medium team members.

Share:
Picture of Mohamed Hussein

Mohamed Hussein

With a BA in Journalism and over 11 years of experience in Arabic and English media, I bring a newsroom mindset to the fast-paced world of crypto content. From breaking news to in-depth features, I’ve worked across leading platforms. Today, as a content writer in the Web3 space, I aim to make complex topics like blockchain, crypto, and digital innovation accessible to a wider audience, without compromising clarity or credibility.
X

Table of Contents

Latest Posts