As the digital finance ecosystem matures, it’s also becoming a prime target for state-linked actors and criminal groups. In July 2025 alone, researchers uncovered North Korean malware campaigns, an evolving ClickFix tactic, and a massive phishing operation using fake Firefox extensions to harvest crypto wallet credentials.
Nim Malware Campaign Targets Web3 via macOS
North Korea-linked threat actors have been caught using Nim, an uncommon but powerful programming language, to develop a new malware family dubbed NimDoor. Targeting Web3 and crypto businesses, this macOS-focused malware uses process injection, TLS-encrypted WebSocket communication, and persistence via system signals (SIGINT, SIGTERM).
Victims are approached on Telegram with fake Zoom meeting invites. Through AppleScript-based loaders, they unknowingly install multi-stage malware that hijacks browser credentials, Telegram data, and system-level information. One binary, CoreKitAgent, ensures the malware survives termination attempts and system reboots.
The chain also includes InjectWithDyldArm64, a loader that injects decrypted trojans into suspended processes—a rare and complex tactic for macOS environments.
ClickFix and BabyShark: Kimsuky Strikes Again
North Korea’s Kimsuky APT group has revived its “ClickFix” social engineering playbook under the BabyShark campaign, now targeting South Korean and U.S. national security experts. The phishing tactics include impersonating journalists, government officials, and diplomats.
Once the user opens a fake document or link, PowerShell commands, malicious scripts, and remote desktop tools like Chrome Remote Desktop are deployed. Some attacks even prompted users to enter authentication codes or use fake CAPTCHA pages—tactics designed to cloak malware under legitimate-looking actions.
Investigations revealed infrastructure leaks including directory listing vulnerabilities and exfiltrated data hosted on a compromised South Korean C2 server.
⚠️ Over 40 Fake Firefox Wallet Extensions Found
In parallel, cybersecurity firm Koi Security has uncovered an ongoing campaign involving over 40 malicious Firefox extensions impersonating major crypto wallets like MetaMask, Coinbase, Trust Wallet, Phantom, and Exodus.
These extensions—uploaded as recently as last week—clone the appearance and branding of real wallets, even reusing open-source code to maintain expected functionality. Hidden inside is malicious code that captures wallet credentials directly from target websites and exfiltrates them to attacker-controlled servers.
“This low-effort, high-impact approach allowed the actor to maintain expected user experience while reducing the chances of immediate detection.” — Koi Security
Many of the extensions had fake five-star reviews, making them harder to detect. Evidence suggests the campaign may be linked to Russian-speaking threat actors, with Russian-language metadata and code comments discovered in the malware files.
🔐 XavierFinans Security Advice
-
Avoid installing browser extensions unless verified by reputable sources.
-
Never run scripts or download files sent via unexpected meeting invites or emails, even if they appear to come from trusted sources.
-
Treat extensions like full software: regularly audit, limit permissions, and disable those no longer in use.
-
Stay updated on APT activity, especially if operating in the crypto, defense, or Web3 space.
State-backed threat actors and independent cybercriminals alike are increasingly targeting the digital finance sector, combining malware, social engineering, and browser hijacking to compromise users and systems. At XavierFinans.com, we’ll continue to track these threats and help safeguard your digital assets.

