North Korean Hackers Target Web3 with Nim Malware and Use ClickFix in BabyShark Campaign
Summary
This article describes North Korean threat actors using Nim-based malware and social engineering to target Web3 and cryptocurrency-related businesses. The attack chain uses fake Zoom update flows, AppleScript, process injection, and credential-stealing payloads to gain persistence and exfiltrate data. It also details the BabyShark campaign’s continued use of ClickFix tactics to deliver remote access tools and malware through phishing and fake portals. The report highlights how these groups keep adapting their tooling, delivery methods, and infrastructure to evade defenses and compromise victims.
Classifications
industries
No industries detected
applications
Data Management
AskAI Classifications
Labels
Cybersecurity Software
Threat Intelligence Platforms
Data Enrichment Software
Linked Companies
Validin
up to $1M