North Korean Hackers Target Web3 with Nim Malware and Use ClickFix in BabyShark Campaign

General News

Summary

This article describes North Korean threat actors using Nim-based malware and social engineering to target Web3 and cryptocurrency-related businesses. The attack chain uses fake Zoom update flows, AppleScript, process injection, and credential-stealing payloads to gain persistence and exfiltrate data. It also details the BabyShark campaign’s continued use of ClickFix tactics to deliver remote access tools and malware through phishing and fake portals. The report highlights how these groups keep adapting their tooling, delivery methods, and infrastructure to evade defenses and compromise victims.

Classifications

industries
No industries detected
applications
Data Management

AskAI Classifications

Labels
Cybersecurity Software Threat Intelligence Platforms Data Enrichment Software

Linked Companies

Validin
up to $1M