
North Korean hackers are reportedly deploying NimDoor malware against Mac computers in Web3 and crypto companies. The threat actors rely on bash scripts to exfiltrate sensitive data, including browser information, iCloud Keychain credentials, and Telegram user data. Like other attacks linked to DPRK threat actors, these also leverage social engineering via chat platforms and malicious scripts or updates to compromise target computers.