menu
techminis

A naukri.com initiative

google-web-stories
source image

Securityaffairs

4d

read

347

img
dot

Image Credit: Securityaffairs

North Korea-linked threat actors spread macOS NimDoor malware via fake Zoom updates

  • North Korea-linked threat actors are spreading macOS NimDoor malware disguised as fake Zoom updates to target Web3 and crypto firms.
  • Victims are lured into installing the backdoor via phishing links sent through Calendly or Telegram, allowing the malware to steal data like browser history and Keychain credentials.
  • The malware, written in Nim, employs encrypted communications, can persist on systems, reinfect itself, and uses process injection techniques along with WebSocket C2 communications for exfiltration.
  • The attackers use a unique mix of AppleScript, C++, and Nim in the NimDoor malware, initiating attacks through fake Zoom invites, with two Mach-O binaries dropped to ensure persistence and data theft.

Read Full Article

like

20 Likes

For uninterrupted reading, download the app