In a targeted cyberattack in April 2025, a North Korea-linked threat group exploited social engineering tactics to breach a macOS system. Posing as a trusted contact on Telegram, the attackers tricked the victim into running a fake “Zoom SDK update” script. This kicked off a sophisticated infection chain that dropped custom malware written in Nim and C++. Dubbed NimDoor, the malware leveraged AppleScript, encrypted communication, and clever persistence tricks to maintain access and steal sensitive information. By blending in with legitimate system tools and using deceptive names, the attackers aimed to silently stay embedded for long-term surveillance and data theft.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox