North Korean Hackers Exploit Web3 with Nim Malware in BabyShark Campaign Using ClickFix

Published:

spot_img

North Korean Hackers Target Web3 and Cryptocurrency Sectors with Advanced Malware

Recent reports have highlighted a concerning trend: North Korean threat actors are increasingly focusing their efforts on Web3 and cryptocurrency-related businesses, employing sophisticated malware written in the Nim programming language. This shift emphasizes the continuous evolution of their tactics in the cyber landscape.

Malware Characteristics and Techniques

In a detailed report by SentinelOne researchers Phil Stokes and Raffaele Sabato, an interesting approach was noted regarding the malware’s capability to inject processes and establish remote communications using wss, the TLS-encrypted version of the WebSocket protocol. This marks a unique approach for macOS malware, showcasing the attackers’ adaptability.

One standout feature of this malicious software is its persistence mechanism, which utilizes SIGINT and SIGTERM signal handlers. This allows the malware to survive system reboots and termination, creating a persistent threat that is difficult to eliminate.

SentinelOne is tracking this malware assortment under the name NimDoor. Interestingly, similar techniques had been recorded earlier by Huntabil.IT, and later by Huntress and Validin, although each documented different payload variants.

Social Engineering Tactics

The attack chains employed by these hackers leverage social engineering techniques. Initial contact often occurs through messaging platforms such as Telegram, where they might arrange a Zoom meeting. An email is sent, claiming to provide a Zoom link that encourages recipients to run a script aimed at updating their Zoom SDK. This seemingly harmless step leads the user to execute an AppleScript that downloads a secondary script from a remote server, cloaked beneath the guise of a legitimate Zoom redirect link.

The downloaded script plays a pivotal role. It unpacks ZIP files containing binaries that establish persistence within the system and initiate additional information-stealing scripts.

The Infection Chain

Central to this infection approach is a C++ loader named InjectWithDyldArm64 (or InjectWithDyld). This loader decrypts two embedded binaries, dubbed Target and trojan1_arm64. The loader executes Target in a suspended state, subsequently injecting the trojan’s code into it before resuming the process.

Once operational, this malware establishes a connection to a designated server to fetch commands. These commands enable it to gather system information, execute arbitrary actions, and adjust its operating directory. The executed results are then relayed back to the command-and-control (C2) server.

Trojan1_arm64 enhances this by downloading additional payloads designed to extract sensitive information from various web browsers, including Chrome, Firefox, and Brave, as well as data from the Telegram application.

Furthermore, the attacks deploy Nim-based executables that serve as gateways for CoreKitAgent, which actively monitors user attempts to terminate the malware, ensuring ongoing operation.

A Shift Towards macOS Systems

The findings underline a marked increase in North Korean groups specifically targeting macOS systems, harnessing AppleScript as a post-exploitation backdoor for extensive data collection. Researchers indicate that these actors have previously experimented with programming languages like Go and Rust, but Nim’s unique capabilities facilitate more complex behaviors within its binaries, reducing visibility and increasing effectiveness.

Kimsuky’s Evolving Tactics

Simultaneously, cybersecurity firm Genians reported on Kimsuky’s ongoing adaptation of social engineering methods, specifically their ClickFix strategy. This scheme has involved crafting spear-phishing emails disguised as interview requests, prompting targets to engage with malicious links purportedly leading to RAR files.

In this scenario, a Visual Basic Script within the archive not only simulates opening a harmless Google Docs file in the user’s browser but also executes harmful code in the background. This code establishes a persistent presence on the infected machine while collecting sensitive system information.

The group’s tactics have shifted recently to impersonate high-ranking officials, continuing the trend of spear-phishing targeting sensitive sectors, particularly within national security domains.

Continued Innovation and Threat Management

As the cyber threat landscape continuously evolves, North Korean hackers, particularly Kimsuky, demonstrate a unique ability to employ new strategies and techniques for malware delivery. These include using GitHub for infrastructure management, exploiting its features to deploy malicious software, and ensuring efficient data exfiltration.

Moreover, the recent surge in phishing campaigns that masquerade as communications from academic institutions underscores the group’s persistent drive to target various sectors under the pretense of benign activities.

With the cyber warfare landscape in constant flux, organizations must remain vigilant, adopting advanced security measures to guard against such sophisticated threats. Protecting sensitive information in this new era of cyber capabilities requires not just awareness but also proactive strategies and robust defenses tailored to defend against evolving tactics.

spot_img

Related articles

Recent articles

Hackers used autonomous AI agent to conduct cyber-espionage on Thailand’s Ministry of Finance

Researchers from cybersecurity firm Hunt.io have reported a cyber-espionage campaign targeting Thailand's Ministry of Finance, allegedly conducted using an autonomous artificial intelligence agent. The...

Quantum Cybersecurity Careers Emerge as Top Job Opportunity for the Next Decade

Guest Post By Sudiptaa Paul Choudhury is Chief Marketing Officer at QNu Labs, a global leader in quantum cybersecurity, TEDx speaker and a LinkedIn...

CVE-2025-66376 Exploited in Russian Cyberespionage Campaign Targeting Zimbra Webmail

Unit 42 has issued an advisory regarding a persistent cyberespionage campaign identified as CL-STA-1114, which targets Zimbra webmail systems. This campaign is attributed to...

New macOS malware exploits Telegram sessions to target cryptocurrency wallets, warns SlowMist

Recent findings from blockchain security firm SlowMist reveal a new macOS malware that exploits Telegram sessions to target cryptocurrency wallets. This sophisticated information-stealing malware...