North Korean Hackers Target Crypto Projects With MacOS Exploit

Written By:
Luqman

Reviewed By:
Gopal Solanky

North Korean Hackers Target Crypto Projects With Macos Exploit

Cybersecurity researchers have uncovered a new malware campaign by North Korean state-backed hackers aimed at cryptocurrency companies. This marks an alarming shift toward targeting Apple’s memory protection on macOS systems.

The malware, which hides in what looks like a Zoom update, is designed to infect computers used by developers and project staff. Once active, it can collect passwords, wallet data and internal files, raising the risk for teams building in Web3 and decentralized finance.

SentinelOne published a detailed technical analysis of the threat on 2 July, naming the exploit NimDoor after the obscure Nim programming language it uses. Because Nim is rarely seen on macOS, its use may help the malware evade detection by standard antivirus tools.

In the report, SentinelOne said, “DPRK threat actors are utilizing Nim-compiled binaries and multiple attack chains in a campaign targeting Web3 and crypto-related businesses.” This approach builds on a 2023 operation the firm called Hidden Risk, where similar groups used PDF lures and a clever persistence trick involving macOS’s zshenv file.

Meanwhile, blockchain data firm Chainalysis reported that North Korea-linked attackers stole more than $1 billion worth of crypto last year. The hacks were spread across 20 separate incidents, with stolen funds suspected to support weapons and missile programmes.

Cybersecurity experts urge Web3 companies to strengthen security on Mac devices. This includes blocking suspicious Zoom or Meet scripts, monitoring unsigned files, and reviewing user-level settings for hidden malware. 

Also Read: South Korea’s Upbit Adds MOODENG with KRW, BTC, USDT Trading Pairs


Mobile Only Image

Share This Article
Luqman Abdulkabir- Crypto Journalist at The Crypto Times
By Luqman
Follow:
Luqman Abdulkabir is a Crypto News Writer with 5 years of experience covering cryptocurrencies, consumer technology, AI, gaming, and software. He holds a Bachelor of Science in Materials Science and Engineering and also has a Digital Marketing Certification, giving him a strong mix of technical and content expertise. Luqman focuses on breaking down complex topics and trends in the crypto space to keep readers informed and up to date.
Follow:
Gopal Solanky is a Research Analyst and Writer with over 5 years of experience in DeFi, blockchain, crypto, IT, and financial markets. With a Bachelor's in Computer Applications, he brings a strong technical foundation to his analysis and reporting. Gopal focuses on breaking down complex topics for both seasoned investors and curious readers. His work has been referenced by publications like Business Insider and Vulture.com, highlighting his contributions to industry stories around topics like Huwak Tuah Memecoin and the FTX collapse.