Binance Square

hack

944,181 مشاهدات
562 يقومون بالنقاش
CryptoInMENA
·
--
🚨 عاجل | حادثة اختراق كبرى في السوق تعرض الحساب المرتبط بـ Sillytuna لعملية ابتزاز عنيفة، نتج عنها سرقة 23.6 مليون $aEthUSDC (بقيمة تقارب 23.6 مليون دولار). 🔎 تفاصيل التحركات حتى الآن: تم تحويل الجزء الأكبر من الأموال إلى 20.34 مليون $DAI جزء آخر يجري تحويله عبر شبكة Arbitrum ثم إيداعه على منصة Hyperliquid لشراء عملة $XMR ⚠️ التحركات تشير إلى محاولة تمويه وتتبع معقد للأموال. ⚠️ تذكير مهم: أمّن محافظك جيدًا، وابتعد عن الروابط المشبوهة أو أي تواصل خارج القنوات الرسمية. السوق لا يرحم من يهمل الأمان. #Crypto #CryptoNews #Blockchain #DeFi #Arbitrum #Hyperliquid #Security #Hack #OnChain #RiskManagement
🚨 عاجل | حادثة اختراق كبرى في السوق

تعرض الحساب المرتبط بـ Sillytuna لعملية ابتزاز عنيفة، نتج عنها سرقة
23.6 مليون $aEthUSDC (بقيمة تقارب 23.6 مليون دولار).

🔎 تفاصيل التحركات حتى الآن:

تم تحويل الجزء الأكبر من الأموال إلى 20.34 مليون $DAI

جزء آخر يجري تحويله عبر شبكة Arbitrum

ثم إيداعه على منصة Hyperliquid لشراء عملة $XMR

⚠️ التحركات تشير إلى محاولة تمويه وتتبع معقد للأموال.

⚠️ تذكير مهم:
أمّن محافظك جيدًا، وابتعد عن الروابط المشبوهة أو أي تواصل خارج القنوات الرسمية.
السوق لا يرحم من يهمل الأمان.

#Crypto #CryptoNews #Blockchain #DeFi #Arbitrum #Hyperliquid #Security #Hack #OnChain #RiskManagement
$24 MILLION DRAINED. RANSOM. AXE THREATS. Entry: 0.999 🟩 Target 1: 1.00 🎯 Stop Loss: 0.995 🛑 CHAOS ERUPTS. aEthUSDC victimized in vicious supply chain attack. Millions gone. Attacker wields violence, weapon threats to extort funds. Victim survives, but funds lost. Bounty offered for recovery. The market is bleeding. Act now. This is not a drill. The stakes are critical. Prepare for extreme volatility. Disclaimer: This is not financial advice. #CryptoNews #Hack #DeFi 🚨
$24 MILLION DRAINED. RANSOM. AXE THREATS.

Entry: 0.999 🟩
Target 1: 1.00 🎯
Stop Loss: 0.995 🛑

CHAOS ERUPTS. aEthUSDC victimized in vicious supply chain attack. Millions gone. Attacker wields violence, weapon threats to extort funds. Victim survives, but funds lost. Bounty offered for recovery. The market is bleeding. Act now. This is not a drill. The stakes are critical. Prepare for extreme volatility.

Disclaimer: This is not financial advice.

#CryptoNews #Hack #DeFi 🚨
Sillytuna Drained! Millions Vanish. Attackers hit Sillytuna hard. 23.6M aEthUSDC gone. They're cashing out fast, converting ~20.34M to DAI. More funds are being bridged, targeting XMR to hide their tracks. This is chaos. The market will react. Stay sharp. Do your own research. #CryptoNews #Hack #SecurityAlert #Blockchain 🚨
Sillytuna Drained! Millions Vanish.

Attackers hit Sillytuna hard. 23.6M aEthUSDC gone. They're cashing out fast, converting ~20.34M to DAI. More funds are being bridged, targeting XMR to hide their tracks. This is chaos. The market will react. Stay sharp.

Do your own research.

#CryptoNews #Hack #SecurityAlert #Blockchain 🚨
$24 MILLION GONE IN SECONDS! Exploit Alert: aEthUSDC flash loan attack. Millions drained. Attacker wallets hold 20 million DAI. Funds are being bridged to Arbitrum. Recovery bounty offered: 10% for funds returned. Act fast. Disclaimer: This is not financial advice. #CryptoNews #DeFi #Hack #Security 🚨
$24 MILLION GONE IN SECONDS!

Exploit Alert: aEthUSDC flash loan attack. Millions drained. Attacker wallets hold 20 million DAI. Funds are being bridged to Arbitrum. Recovery bounty offered: 10% for funds returned. Act fast.

Disclaimer: This is not financial advice.

#CryptoNews #DeFi #Hack #Security 🚨
$24 MILLION GONE IN SECONDS Flash loan attack drains aEthUSDC. Attacker holding 20 million DAI. Funds are moving. Recovery bounty announced: 10% for return. This is chaos. Act now. Disclaimer: This is not financial advice. #DeFi #Hack #Crypto #ARBİTRUM 🚨
$24 MILLION GONE IN SECONDS

Flash loan attack drains aEthUSDC. Attacker holding 20 million DAI. Funds are moving. Recovery bounty announced: 10% for return. This is chaos. Act now.

Disclaimer: This is not financial advice.

#DeFi #Hack #Crypto #ARBİTRUM 🚨
INVERSE FINANCE EXPOSED. 240K GONE. BlockSec confirms Inverse Finance under attack. DOLA price manipulation suspected. Mass liquidations triggered. BlockSec reached out. No response yet. This is chaos. Disclaimer: This is not financial advice. #DeFi #Hack #CryptoSecurity 🚨
INVERSE FINANCE EXPOSED. 240K GONE.

BlockSec confirms Inverse Finance under attack. DOLA price manipulation suspected. Mass liquidations triggered. BlockSec reached out. No response yet. This is chaos.

Disclaimer: This is not financial advice.

#DeFi #Hack #CryptoSecurity 🚨
🇯🇵🕵️ Former Mt. Gox CEO proposed conducting a one-time hard fork of #BTC to recover 79,956 #BTC (~$5.2 billion) from a hacker's address for the creditors’ repayment. #hack #crypto
🇯🇵🕵️ Former Mt. Gox CEO proposed conducting a one-time hard fork of #BTC to recover 79,956 #BTC (~$5.2 billion) from a hacker's address for the creditors’ repayment. #hack

#crypto
HÀN QUỐC RÒ RỈ KHÓA VÍ, 4.8 TRIỆU USD BAY MÀU! CƠ QUAN THUẾ HÀN QUỐC VÔ TÌNH LÀM LỘ THÔNG TIN KHÔI PHỤC VÍ. TOKEN TRỊ GIÁ 4.8 TRIỆU USD ĐÃ BỊ ĐÁNH CẮP. THỊ TRƯỜNG ĐANG BIẾN ĐỘNG MẠNH. ĐÂY LÀ CẢNH BÁO KHẨN CẤP CHO TẤT CẢ NHÀ ĐẦU TƯ. AN NINH VÍ CỦA BẠN LÀ TRÁCH NHIỆM CỦA BẠN. ĐỪNG CHỦ QUAN. HÀNH ĐỘNG NGAY BÂY GIỜ. THÔNG TIN NÀY QUAN TRỌNG NHẤT TRONG NGÀY. TUYÊN BỐ MIỄN TRỪ TRÁCH NHIỆM: GIAO DỊCH TIỀN ĐIỆN TỬ CÓ RỦI RO CAO. #CryptoAlert #Hack #Security #Bitcoin #Ethereum 🚨
HÀN QUỐC RÒ RỈ KHÓA VÍ, 4.8 TRIỆU USD BAY MÀU!

CƠ QUAN THUẾ HÀN QUỐC VÔ TÌNH LÀM LỘ THÔNG TIN KHÔI PHỤC VÍ. TOKEN TRỊ GIÁ 4.8 TRIỆU USD ĐÃ BỊ ĐÁNH CẮP. THỊ TRƯỜNG ĐANG BIẾN ĐỘNG MẠNH. ĐÂY LÀ CẢNH BÁO KHẨN CẤP CHO TẤT CẢ NHÀ ĐẦU TƯ. AN NINH VÍ CỦA BẠN LÀ TRÁCH NHIỆM CỦA BẠN. ĐỪNG CHỦ QUAN. HÀNH ĐỘNG NGAY BÂY GIỜ. THÔNG TIN NÀY QUAN TRỌNG NHẤT TRONG NGÀY.

TUYÊN BỐ MIỄN TRỪ TRÁCH NHIỆM: GIAO DỊCH TIỀN ĐIỆN TỬ CÓ RỦI RO CAO.

#CryptoAlert #Hack #Security #Bitcoin #Ethereum 🚨
GOVT LEAKS WALLET SEED PHRASE! $PRTG GONE! National Tax Service just exposed a crypto wallet's mnemonic phrase. Hackers struck immediately. Millions in $PRTG tokens vanished. This is a catastrophic security fail. Law enforcement clearly out of their depth. Digital assets are too valuable to be handled this carelessly. This mistake cost millions. Disclaimer: This is not financial advice. #CryptoNews #Hack #SecurityFail #DigitalAssets 🚨
GOVT LEAKS WALLET SEED PHRASE! $PRTG GONE!

National Tax Service just exposed a crypto wallet's mnemonic phrase. Hackers struck immediately. Millions in $PRTG tokens vanished. This is a catastrophic security fail. Law enforcement clearly out of their depth. Digital assets are too valuable to be handled this carelessly. This mistake cost millions.

Disclaimer: This is not financial advice.

#CryptoNews #Hack #SecurityFail #DigitalAssets 🚨
FOOM CASH HACKED! $2.26M GONE. Privacy gaming platform FOOM CASH suffered a devastating attack on Base and Ethereum. Over 24 TRILLION FOOM tokens vanished. The exploit stemmed from a critical verification key misconfiguration. An attacker forged a zkSNARK proof to drain the compromised contract. This is a massive blow to user trust and security. Act fast to protect your assets. Disclaimer: This is not financial advice. #crypto #hack #security #blockchain 💥
FOOM CASH HACKED! $2.26M GONE.

Privacy gaming platform FOOM CASH suffered a devastating attack on Base and Ethereum. Over 24 TRILLION FOOM tokens vanished. The exploit stemmed from a critical verification key misconfiguration. An attacker forged a zkSNARK proof to drain the compromised contract. This is a massive blow to user trust and security. Act fast to protect your assets.

Disclaimer: This is not financial advice.
#crypto #hack #security #blockchain 💥
Lebih dari $1,46 miliar telah mengalir keluar dari #Bybit dalam waktu singkat INI BISA MENJADI #HACK BESAR-BESARAN
Lebih dari $1,46 miliar
telah mengalir keluar dari #Bybit dalam waktu singkat

INI BISA MENJADI #HACK
BESAR-BESARAN
·
--
صاعد
The details of the recent hack on Bybit are continuing to emerge. Hackers successfully stole around 135,000 Ethereum, worth approximately $335 million, from the platform's hot wallets. Investigations show that the hackers managed to launder 45,900 ETH (around $113 million) within a very short period. At this rate, it’s estimated that the remaining stolen Ethereum could be fully laundered in just 8 to 10 days. In response, Bybit assured users that their funds are safe and that investigations into the attack are ongoing. The hackers have been using decentralized platforms to quickly launder the stolen Ethereum, highlighting the need for cryptocurrency exchanges and the broader crypto community to reassess their security measures. #bybit #Hack
The details of the recent hack on Bybit are continuing to emerge. Hackers successfully stole around 135,000 Ethereum, worth approximately $335 million, from the platform's hot wallets. Investigations show that the hackers managed to launder 45,900 ETH (around $113 million) within a very short period. At this rate, it’s estimated that the remaining stolen Ethereum could be fully laundered in just 8 to 10 days.

In response, Bybit assured users that their funds are safe and that investigations into the attack are ongoing. The hackers have been using decentralized platforms to quickly launder the stolen Ethereum, highlighting the need for cryptocurrency exchanges and the broader crypto community to reassess their security measures.

#bybit #Hack
⚠️ Beware of the new malware RatOn. It targets Android devices, hacks wallets (MetaMask, Trust, Phantom) and banking apps, and can even lock your screen for ransom. Active since July, spreading through fake TikTok apps. When your whole life is on your phone, device security must come first. Get proper antivirus and run regular checks. #scam #Android #Hack #tiktok #fake
⚠️ Beware of the new malware RatOn. It targets Android devices, hacks wallets (MetaMask, Trust, Phantom) and banking apps, and can even lock your screen for ransom. Active since July, spreading through fake TikTok apps.

When your whole life is on your phone, device security must come first. Get proper antivirus and run regular checks.
#scam #Android #Hack #tiktok #fake
#SBIGroup Crypto Loses $21M in Suspected North Korean #Hack Blockchain investigator ZachXBT reported Wednesday that addresses linked to SBI Group Crypto lost approximately $21 million on September 24. The stolen funds included $BTC , $ETH , $LTC , $DOGE, and Bitcoin Cash, which were subsequently laundered through Tornado Cash. SBI Crypto operates as a subsidiary of Japanese financial conglomerate SBI Group. The company did not immediately respond to requests for comment regarding the incident. Blockchain security firm Cyvers assisted #ZachXBT with the investigation. The attack exhibits characteristics similar to other exploits connected to North Korean #hackers. Stolen funds were routed through instant exchanges before being deposited into Tornado Cash, a decentralized mixing protocol designed to obscure transaction origins. ZachXBT has established a reputation as one of the most prolific cryptocurrency investigators, identifying numerous instances of illicit fund movements. In June, the sleuth reported that Iranian cryptocurrency exchange Nobitex appeared compromised for over $80 million across Tron and EVM-compatible chains. Earlier this year, Arkham Intelligence attributed the Bybit hack involving over $1.5 billion to Lazarus Group, widely believed to operate under North Korean state sponsorship. The attribution cited information provided by ZachXBT. #TornadoCash has faced sustained scrutiny as a platform enabling hackers to launder stolen funds. The Treasury Department's Office of Foreign Assets Control sanctioned the protocol in August 2022. Roman Storm faced charges in 2023 for conspiracy to commit money laundering and sanctions violations related to operating Tornado Cash.
#SBIGroup Crypto Loses $21M in Suspected North Korean #Hack

Blockchain investigator ZachXBT reported Wednesday that addresses linked to SBI Group Crypto lost approximately $21 million on September 24. The stolen funds included $BTC , $ETH , $LTC , $DOGE, and Bitcoin Cash, which were subsequently laundered through Tornado Cash.

SBI Crypto operates as a subsidiary of Japanese financial conglomerate SBI Group. The company did not immediately respond to requests for comment regarding the incident. Blockchain security firm Cyvers assisted #ZachXBT with the investigation.

The attack exhibits characteristics similar to other exploits connected to North Korean #hackers. Stolen funds were routed through instant exchanges before being deposited into Tornado Cash, a decentralized mixing protocol designed to obscure transaction origins.

ZachXBT has established a reputation as one of the most prolific cryptocurrency investigators, identifying numerous instances of illicit fund movements. In June, the sleuth reported that Iranian cryptocurrency exchange Nobitex appeared compromised for over $80 million across Tron and EVM-compatible chains.

Earlier this year, Arkham Intelligence attributed the Bybit hack involving over $1.5 billion to Lazarus Group, widely believed to operate under North Korean state sponsorship. The attribution cited information provided by ZachXBT.

#TornadoCash has faced sustained scrutiny as a platform enabling hackers to launder stolen funds. The Treasury Department's Office of Foreign Assets Control sanctioned the protocol in August 2022. Roman Storm faced charges in 2023 for conspiracy to commit money laundering and sanctions violations related to operating Tornado Cash.
30.1K #BTC ($2.1B) of #Silk Road #hack funds controlled by US government is on the move right now. 0.001 BTC ($69) transferred to a Coinbase deposit address so it’s a test transfer possibly. txn hash 9c3af4b48e66565f1da1da8278036fa1dbb09f2beaaca99c3504475390ba4590 Coinbase deposit address 3KrZVU9Jz4UKHpKUtuvkEMX1tY8zeiTvX2
30.1K #BTC ($2.1B) of #Silk Road #hack funds controlled by US government is on the move right now.

0.001 BTC ($69) transferred to a Coinbase deposit address so it’s a test transfer possibly.

txn hash
9c3af4b48e66565f1da1da8278036fa1dbb09f2beaaca99c3504475390ba4590

Coinbase deposit address
3KrZVU9Jz4UKHpKUtuvkEMX1tY8zeiTvX2
MAKINA WIPED OUT. HUGE LOSS. 5,107,871 USDC GONE. The multi-chain DeFi execution engine Makina was just hit hard on Ethereum. Attackers exploited a vulnerability. They manipulated pool prices. They inflated LP assets. Arbitrage attack executed. This is a massive blow. Don't get caught in the crossfire. Stay sharp. Disclaimer: This is not financial advice. #DeFi #Hack #CryptoNews 🚨
MAKINA WIPED OUT. HUGE LOSS.

5,107,871 USDC GONE.

The multi-chain DeFi execution engine Makina was just hit hard on Ethereum. Attackers exploited a vulnerability. They manipulated pool prices. They inflated LP assets. Arbitrage attack executed. This is a massive blow. Don't get caught in the crossfire. Stay sharp.

Disclaimer: This is not financial advice.

#DeFi #Hack #CryptoNews 🚨
#ScrollCoFounderXAccountHacked Bigger Lesson for Web3 Founders 🔐 #ScrollCoFounderXAccountHacked This incident is another wake-up call for Web3 founders and teams. As public-facing figures, their accounts carry massive influence and are prime targets for hackers. A single compromised post can lead to financial losses for followers and reputational damage for projects. Best practices like hardware-based 2FA, limited access permissions, and rapid response protocols are no longer optional. For users, the key takeaway is simple: never trust announcements blindly—even from well-known founders—without cross-checking official project channels #Hack #HackerAlert #Hacked
#ScrollCoFounderXAccountHacked
Bigger Lesson for Web3 Founders
🔐 #ScrollCoFounderXAccountHacked
This incident is another wake-up call for Web3 founders and teams. As public-facing figures, their accounts carry massive influence and are prime targets for hackers. A single compromised post can lead to financial losses for followers and reputational damage for projects. Best practices like hardware-based 2FA, limited access permissions, and rapid response protocols are no longer optional. For users, the key takeaway is simple: never trust announcements blindly—even from well-known founders—without cross-checking official project channels
#Hack #HackerAlert #Hacked
🔥 Scammers on the Rise: How the Meme Coin Boom on Solana Unlocked New Ways to Steal Millions 💸🌐 The Crypto Market in Shock! In 2024, total Web3 losses exceeded $2.9 billion. From DeFi to metaverses, no sector was spared. 🚨 The main vulnerability? Access control issues, responsible for 78% of all attacks. 💎 DeFi: Fewer losses, but major hacks persist Losses decreased by 40%, but still reached $474 million. The biggest incident was the hack of Radiant Capital, costing $55 million. 🏦 CeFi in Trouble: Losses Double! CeFi losses skyrocketed to $694 million. Notable attacks include a key leak at DMM Exchange ($305 million) and a multisignature vulnerability at WazirX ($230 million). 🎮 Games and Metaverses Lose Hundreds of Millions The gaming sector reported $389 million in losses, accounting for 18% of all attacks. 🎲 🚩 Rug Pulls Shift to Solana Scammers moved from BNB Chain to Solana, driven by the growing popularity of meme coins. 📈 🎯 Presales Turn into Traps: $122.5 Million Stolen in One Month! In April 2024, scammers executed 27 fraud schemes using presales. 💰 They also exploited the names of celebrities and influencers to deceive investors. 👨‍💻 Phishing and North Korean Hackers Phishing attacks led to $600 million in stolen funds, while North Korean hackers siphoned off $1.34 billion. ⚠️ Stay Alert! Crypto scams are becoming increasingly sophisticated. 🛡️ Behind every meme coin, a trap could be waiting! #Hack #scamriskwarning #solana

🔥 Scammers on the Rise: How the Meme Coin Boom on Solana Unlocked New Ways to Steal Millions 💸

🌐 The Crypto Market in Shock!
In 2024, total Web3 losses exceeded $2.9 billion. From DeFi to metaverses, no sector was spared. 🚨 The main vulnerability? Access control issues, responsible for 78% of all attacks.

💎 DeFi: Fewer losses, but major hacks persist
Losses decreased by 40%, but still reached $474 million. The biggest incident was the hack of Radiant Capital, costing $55 million.

🏦 CeFi in Trouble: Losses Double!
CeFi losses skyrocketed to $694 million. Notable attacks include a key leak at DMM Exchange ($305 million) and a multisignature vulnerability at WazirX ($230 million).

🎮 Games and Metaverses Lose Hundreds of Millions
The gaming sector reported $389 million in losses, accounting for 18% of all attacks. 🎲

🚩 Rug Pulls Shift to Solana
Scammers moved from BNB Chain to Solana, driven by the growing popularity of meme coins. 📈

🎯 Presales Turn into Traps: $122.5 Million Stolen in One Month!
In April 2024, scammers executed 27 fraud schemes using presales. 💰 They also exploited the names of celebrities and influencers to deceive investors.

👨‍💻 Phishing and North Korean Hackers
Phishing attacks led to $600 million in stolen funds, while North Korean hackers siphoned off $1.34 billion.

⚠️ Stay Alert!
Crypto scams are becoming increasingly sophisticated. 🛡️ Behind every meme coin, a trap could be waiting!
#Hack #scamriskwarning #solana
North Korean Hackers Target Crypto with Nim-Based Malware Disguised as Zoom Updates🔹 Fake Zoom meeting invites and update links deceive Web3 teams 🔹 New NimDoor malware infiltrates macOS with advanced evasion techniques 🔹 Attackers steal browser data, passwords, and Telegram chats Web3 and Crypto Companies Under Siege by NimDoor Malware Security experts at SentinelLabs have uncovered a sophisticated malware campaign targeting Web3 startups and cryptocurrency firms. The attacks, linked to North Korean groups, use a combination of social engineering and technical stealth to deploy NimDoor malware, written in the rarely used Nim programming language to bypass antivirus detection. The Setup: Fake Zoom Meetings Through Telegram Hackers initiate contact via Telegram, posing as known contacts. They invite victims to schedule meetings via Calendly, then send them links to what appear to be Zoom software updates. These links lead to fake domains like support.us05web-zoom.cloud, mimicking Zoom's legitimate URLs and hosting malicious installation files. These files contain thousands of lines of whitespace, making them appear "legitimately large." Hidden within are only three crucial lines of code, which download and execute the real attack payload. NimDoor Malware: Spyware Specifically Targeting macOS Once executed, the NimDoor malware operates in two main phases: 🔹 Data extraction – stealing saved passwords, browsing histories, and login credentials from popular browsers like Chrome, Firefox, Brave, Edge, and Arc. 🔹 System persistence – maintaining long-term access through stealth background processes and disguised system files. A key component specifically targets Telegram, stealing encrypted chat databases and decryption keys, giving attackers access to private conversations offline. Built to Survive: Evasion and Reinstallation Techniques NimDoor employs a range of advanced persistence mechanisms: 🔹 Automatically reinstalls itself if users try to terminate or delete it 🔹 Creates hidden files and folders that look like legitimate macOS system components 🔹 Connects to the attacker’s server every 30 seconds for instructions, disguised as normal internet traffic 🔹 Delays execution for 10 minutes to avoid early detection by security software Difficult to Remove Without Professional Tools Because of these techniques, NimDoor is extremely hard to remove with standard tools. Specialized security software or professional intervention is often required to clean infected systems completely. Conclusion: Modern Cyberattacks Now Look Like Calendar Invites Attacks like NimDoor prove how cleverly North Korean groups mimic daily workflows to penetrate even cautious targets. Fake Zoom links and innocent-looking updates can lead to full system compromise. Users should never download updates from unofficial sources, always verify domain names, and stay vigilant against unexpected software prompts or invitations. #CyberSecurity , #NorthKoreaHackers , #Web3Security , #CryptoNews , #Hack Stay one step ahead – follow our profile and stay informed about everything important in the world of cryptocurrencies! Notice: ,,The information and views presented in this article are intended solely for educational purposes and should not be taken as investment advice in any situation. The content of these pages should not be regarded as financial, investment, or any other form of advice. We caution that investing in cryptocurrencies can be risky and may lead to financial losses.“

North Korean Hackers Target Crypto with Nim-Based Malware Disguised as Zoom Updates

🔹 Fake Zoom meeting invites and update links deceive Web3 teams

🔹 New NimDoor malware infiltrates macOS with advanced evasion techniques

🔹 Attackers steal browser data, passwords, and Telegram chats

Web3 and Crypto Companies Under Siege by NimDoor Malware
Security experts at SentinelLabs have uncovered a sophisticated malware campaign targeting Web3 startups and cryptocurrency firms. The attacks, linked to North Korean groups, use a combination of social engineering and technical stealth to deploy NimDoor malware, written in the rarely used Nim programming language to bypass antivirus detection.

The Setup: Fake Zoom Meetings Through Telegram
Hackers initiate contact via Telegram, posing as known contacts. They invite victims to schedule meetings via Calendly, then send them links to what appear to be Zoom software updates. These links lead to fake domains like support.us05web-zoom.cloud, mimicking Zoom's legitimate URLs and hosting malicious installation files.
These files contain thousands of lines of whitespace, making them appear "legitimately large." Hidden within are only three crucial lines of code, which download and execute the real attack payload.

NimDoor Malware: Spyware Specifically Targeting macOS
Once executed, the NimDoor malware operates in two main phases:
🔹 Data extraction – stealing saved passwords, browsing histories, and login credentials from popular browsers like Chrome, Firefox, Brave, Edge, and Arc.

🔹 System persistence – maintaining long-term access through stealth background processes and disguised system files.
A key component specifically targets Telegram, stealing encrypted chat databases and decryption keys, giving attackers access to private conversations offline.

Built to Survive: Evasion and Reinstallation Techniques
NimDoor employs a range of advanced persistence mechanisms:
🔹 Automatically reinstalls itself if users try to terminate or delete it

🔹 Creates hidden files and folders that look like legitimate macOS system components

🔹 Connects to the attacker’s server every 30 seconds for instructions, disguised as normal internet traffic

🔹 Delays execution for 10 minutes to avoid early detection by security software

Difficult to Remove Without Professional Tools
Because of these techniques, NimDoor is extremely hard to remove with standard tools. Specialized security software or professional intervention is often required to clean infected systems completely.

Conclusion: Modern Cyberattacks Now Look Like Calendar Invites
Attacks like NimDoor prove how cleverly North Korean groups mimic daily workflows to penetrate even cautious targets. Fake Zoom links and innocent-looking updates can lead to full system compromise.
Users should never download updates from unofficial sources, always verify domain names, and stay vigilant against unexpected software prompts or invitations.

#CyberSecurity , #NorthKoreaHackers , #Web3Security , #CryptoNews , #Hack

Stay one step ahead – follow our profile and stay informed about everything important in the world of cryptocurrencies!
Notice:
,,The information and views presented in this article are intended solely for educational purposes and should not be taken as investment advice in any situation. The content of these pages should not be regarded as financial, investment, or any other form of advice. We caution that investing in cryptocurrencies can be risky and may lead to financial losses.“
سجّل الدخول لاستكشاف المزيد من المُحتوى
استكشف أحدث أخبار العملات الرقمية
⚡️ كُن جزءًا من أحدث النقاشات في مجال العملات الرقمية
💬 تفاعل مع صنّاع المُحتوى المُفضّلين لديك
👍 استمتع بالمحتوى الذي يثير اهتمامك
البريد الإلكتروني / رقم الهاتف