Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
What's Hot

How Low Will Bitcoin Price Go After 13% Crash?

June 4, 2026

Banks’ survey says people don’t want to rock the boat if stablecoin yield risks lending

June 4, 2026

Legendary Trader Peter Brandt Details Downside Price Target for Bitcoin After BTC Breaks From ‘Reliable’ Pattern

June 4, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    How Low Will Bitcoin Price Go After 13% Crash?

    June 4, 2026

    Legendary Trader Peter Brandt Details Downside Price Target for Bitcoin After BTC Breaks From ‘Reliable’ Pattern

    June 4, 2026

    Standard Chartered’s three ‘Ifs’ that stand between bitcoin and a market low: Crypto Daily

    June 4, 2026

    Bitcoin Price Plunges Below $62,000, Erasing Months Of Gains

    June 4, 2026

    Tom Lee’s BitMine Seeks $300 Million Raise to Buy More Ethereum

    June 4, 2026

    Ethereum Crashes 60% As Analysts Dump ETH And Rotate Into These Altcoins

    June 4, 2026

    Ethereum Weakness May Be Final Phase Before Next Market Expansion

    June 4, 2026

    Ethereum’s Multi-Year Support Test Could Shape Its Next Big Move

    June 4, 2026

    Bitcoin’s $60K Range Seen As Potential Long-Term Accumulation Zone, Analyst Says

    June 4, 2026

    JPMorgan Chase CEO Speaks Out Against Clarity Act, Says Banks Will Fight Bill in Upcoming Markup

    June 4, 2026

    Bitcoin Traders Turn Most Fearful In 2 Months Following Crash

    June 4, 2026

    The Rapid XRP Growth Trajectory That Investors Should Be Aware Of

    June 4, 2026

    Meme Coin Market Faces Imbalance as Supply Rises, Demand Falls

    April 4, 2026

    Crypto Interest Rising Toward Meme Coin Sector

    January 9, 2026

    Memes Market Cap Adds $10B in Days: Fresh Capital or Dead-Cat-Bounce?

    January 5, 2026

    Meme Coin Market Surges Past $45B as Shiba Inu, PEPE, BONK Stage 54% Price Pump

    January 4, 2026

    How Low Will Bitcoin Price Go After 13% Crash?

    June 4, 2026

    Banks’ survey says people don’t want to rock the boat if stablecoin yield risks lending

    June 4, 2026

    Legendary Trader Peter Brandt Details Downside Price Target for Bitcoin After BTC Breaks From ‘Reliable’ Pattern

    June 4, 2026

    Bitcoin’s $60K Range Seen As Potential Long-Term Accumulation Zone, Analyst Says

    June 4, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Top Crypto Events to Watch This Week Across Europe and Beyond

    June 4, 2026

    Tezos Unveils TzEL, an Experimental Post‑Quantum Privacy Rollup

    June 4, 2026

    why big banks hesitate in front of blockchain

    June 4, 2026

    ENI Integrates X-Agent into Super Node Network to Build Next Gen Web3 Applications

    June 4, 2026

    Infosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark Web

    June 3, 2026

    Stake DAO Freezes Arbitrum vsdCRV Markets After Attacker Mints 5.4T Synthetic Tokens

    May 29, 2026

    Certik Unveils ‘Anti-Virus for AI Agents’ as Skill Marketplaces Face Hidden Threats

    May 29, 2026

    New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

    May 28, 2026

    How Low Will Bitcoin Price Go After 13% Crash?

    June 4, 2026

    Banks’ survey says people don’t want to rock the boat if stablecoin yield risks lending

    June 4, 2026

    Legendary Trader Peter Brandt Details Downside Price Target for Bitcoin After BTC Breaks From ‘Reliable’ Pattern

    June 4, 2026

    Bitcoin’s $60K Range Seen As Potential Long-Term Accumulation Zone, Analyst Says

    June 4, 2026
  • Web 3
    1. Gaming
    2. View All

    Pi Network Expands Gaming Ecosystem as CiDi Games Launches Developer Center

    June 3, 2026

    GMATRIXS Taps GamePad to Boost Web3 Gaming and DeFi Infrastructure

    June 3, 2026

    Code as Constitution: How Crypto Governance Is Moving Into the Real World

    June 2, 2026

    Why Toncoin Is Rising as Telegram Pushes Past Tap-to-Earn

    June 2, 2026

    How Low Will Bitcoin Price Go After 13% Crash?

    June 4, 2026

    Banks’ survey says people don’t want to rock the boat if stablecoin yield risks lending

    June 4, 2026

    Legendary Trader Peter Brandt Details Downside Price Target for Bitcoin After BTC Breaks From ‘Reliable’ Pattern

    June 4, 2026

    Bitcoin’s $60K Range Seen As Potential Long-Term Accumulation Zone, Analyst Says

    June 4, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    Banks’ survey says people don’t want to rock the boat if stablecoin yield risks lending

    June 4, 2026

    SEC Draft Plan Would Curb Enforcement Reach and Cement Atkins’s Crypto Turn

    June 4, 2026

    Blockchain Association urges Senate to pass Clarity Act with letter from 160 former security officials

    June 4, 2026

    NYDFS and EBA Sign Agreement to Collaborate on Stablecoin Regulation

    June 4, 2026

    Bank of England stablecoin caps may choke the UK’s pound-token market before launch

    June 3, 2026

    Cardano just canceled is 2026 Summit

    June 2, 2026

    Trader turns $2,480 into $12 million after holding Binance memecoin for 8 months

    June 1, 2026

    Crypto walked so banks could run

    May 30, 2026

    How Low Will Bitcoin Price Go After 13% Crash?

    June 4, 2026

    Banks’ survey says people don’t want to rock the boat if stablecoin yield risks lending

    June 4, 2026

    Legendary Trader Peter Brandt Details Downside Price Target for Bitcoin After BTC Breaks From ‘Reliable’ Pattern

    June 4, 2026

    Bitcoin’s $60K Range Seen As Potential Long-Term Accumulation Zone, Analyst Says

    June 4, 2026
  • Analysis

    Wedbush’s Dan Ives Sees 30% Upside for ‘Mispriced’ Mag 7 Stock, Says AI Could Hit Monetization Phase in Coming Months

    June 4, 2026

    Here’s What Traders Are Watching

    June 4, 2026

    Zcash was rumored to have stopped working

    June 4, 2026

    Here’s Why BTC Could Fall to $54K

    June 4, 2026

    Banks pushed Congress to kill stablecoin yield with CLARITY Act

    June 4, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is BChat? The Decentralized Messaging App Built for Privacy

    June 2, 2026

    What Is an AI Prompt Injection Attack? The Hidden Threat Hijacking Your Chatbots

    May 31, 2026

    What Is AI Jailbreaking? A Beginner’s Guide to the Cat-and-Mouse Game Behind Every Chatbot

    May 17, 2026

    What’s on the Ethereum Roadmap: Glamsterdam, Hegota and Beyond

    March 30, 2026

    Vitalik wants DeFi price crashes to stop triggering automatic liquidations

    June 4, 2026

    Mt. Gox-linked wallets moved 10,422 BTC, worth roughly $739 million as BTC price slides

    June 4, 2026

    XRP is sitting on a volatility trap as liquidity dries up and leverage builds

    May 27, 2026

    Kraken moves Bitcoin to Chainlink as bridge fears spread across DeFi

    May 16, 2026

    How Low Will Bitcoin Price Go After 13% Crash?

    June 4, 2026

    Banks’ survey says people don’t want to rock the boat if stablecoin yield risks lending

    June 4, 2026

    Legendary Trader Peter Brandt Details Downside Price Target for Bitcoin After BTC Breaks From ‘Reliable’ Pattern

    June 4, 2026

    Bitcoin’s $60K Range Seen As Potential Long-Term Accumulation Zone, Analyst Says

    June 4, 2026
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»North Korean Hackers Target Crypto Firms with Novel macOS Malware
North Korean Hackers Target Crypto Firms with Novel macOS Malware
Security and Privacy

North Korean Hackers Target Crypto Firms with Novel macOS Malware

September 8, 2025No Comments4 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

North Korean threat actors are deploying novel techniques to infect crypto businesses with macOS malware designed to steal credentials, according to a new report by SentinelLabs.

The researchers provided an analysis on a series of attacks launched by Democratic People’s Republic of Korea (DPRK) threat actors against Web3 and Crypto organizations during April 2025.

North Korea-affiliated attackers have been attributed to a large volume of major cryptocurrency heists in recent years, as part of efforts to generate revenue for the Pyongyang regime.

In Febrary 2025, the notorious DPRK-linked Lazarus Group stole $1.4bn worth of crypto from the ByBit exchange.

NimDoor Malware Deployed

In the new analysis, SentinelLabs researchers observed the attackers using social engineering techniques typical of DPRK actors to achieve initial access.

After gaining access, the attackers then deployed novel tactics, techniques and procedures (TTPs) to achieve persistence and launch the Nim-based malware, known as NimDoor.

The Nim programming language has become increasingly popular among macOS malware authors, partly due to their unfamiliarity to analysts.

The TTPs used by the attackers include an attack chain consisting of an eclectic mix of scripts and binaries written in AppleScript, C++ and Nim.

This approach makes detection harder for defenders.

“North Korean-aligned threat actors have previously experimented with Go and Rust, similarly combining scripts and compiled binaries into multi-stage attack chains,” the researchers wrote.

“However, Nim’s rather unique ability to execute functions during compile time allows attackers to blend complex behavior into a binary with less obvious control flow, resulting in compiled binaries in which developer code and Nim runtime code are intermingled even at the function level,” SentinelLabs researchers said.

See also  PayPal redefines messaging with crypto and cash payment links

The use of wss for communication and signal interrupts is designed to defeat security measures. wss is the TLS-encrypted version of the WebSocket protocol.

The researchers urged analysts to invest in efforts to understand lesser-known programming languages, such as Nim, and how they can be leveraged to defend against these types of attacks.

The Initial Nim Attack Chain

The blog, published on July 2, observed that the April attacks began with a social engineering technique synonymous with DPRK actors – impersonation of a trusted contact over Telegram and an invitation to schedule a meeting via Calendly.

The target was subsequently sent an email containing a Zoom meeting link and instructions to run a so-called “Zoom SDK update script”.

The domain hosted a malicious AppleScript file, which was heavily padded to obfuscate its true function.

The script ended with three lines of malicious code that that retrieve and execute a second-stage script from a command-and-control (C2) server.

The follow-on script downloaded an HTML file which includes a legitimate Zoom redirect link. Upon execution, this file launches the attack’s core logic.

Multi-Stage Infection Process

The researchers observed a complex multistage deployment process for the NimDoor malware, which encompasses a range of scripts and binaries written in various languages.

This starts with the download of two Mach-O binaries, which set off two independent execution chains.

The first is a C++-compiled universal architecture Mach-O executable, which aims to fetch two Bash scripts used for data exfiltration across different browsers.

The second execution chain starts with an installer binary, which is a universal Mach-O executable compiled from Nim source code. This executable is responsible for achieving long-term access and recovery for the threat actor.

See also  SEC issues guidance on crypto asset custody for retail investors

This drops two other binaries onto the victim’s system, called GoogIe LLC and CoreKitAgent.

The misspelling of GoogIe LLC (uppercase I rather than lowercase l), is intended to help the malware blend in and avoid suspicion.

GoogIe sets up a macOS LaunchAgent, which re-launches GoogIe LLC at login and stores authentication keys for later stages.

CoreKitAgent, the most technicaly complex of the binaries analyzed, takes advantage of SIGINT/SIGTERM signal handlers to install persistence when the malware is terminated or the system rebooted.

These are signals users can send to terminate processes. However, when CoreKitAgent catches these signals triggers a reinstallation routine that re-deploys GoogIe LLC.

CoreKitAgent also writes the LaunchAgent for persistence and a copy of itself as the Trojan.

“This behavior ensures that any user-initiated termination of the malware results in the deployment of the core components, making the code resilient to basic defensive actions,” the researchers noted.

Finally, an embedded AppleScript in a stripped version of CoreKitAgent is decoded and launched.

Upon execution, the script beacons to C2 infrastructure every 30 seconds, and attempts to post data obtained from listing all running processes on the victim machine.

Crypto Firms Hackers Korean macOS malware North target
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Legendary Trader Peter Brandt Details Downside Price Target for Bitcoin After BTC Breaks From ‘Reliable’ Pattern

June 4, 2026

SEC Draft Plan Would Curb Enforcement Reach and Cement Atkins’s Crypto Turn

June 4, 2026

Top Crypto Events to Watch This Week Across Europe and Beyond

June 4, 2026

Standard Chartered’s three ‘Ifs’ that stand between bitcoin and a market low: Crypto Daily

June 4, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Here’s What’s Next For Bitcoin And Ethereum

October 13, 2025

Top Reasons Why SOL Price is Poised to Break $220 Barrier

November 10, 2025

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

How Low Will Bitcoin Price Go After 13% Crash?

June 4, 2026

Banks’ survey says people don’t want to rock the boat if stablecoin yield risks lending

June 4, 2026

Legendary Trader Peter Brandt Details Downside Price Target for Bitcoin After BTC Breaks From ‘Reliable’ Pattern

June 4, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.