Cybercriminals are distributing a new malware, but it has a unique feature. It is written in a programming language that is rarely used for malicious code. Proofpoint researchers have named this malware NimzaLoader .

The NimzaLoader malware is written in the Nim. Researchers believe that the hackers behind the malware designed it this way, hoping that choosing an unusual programming language would make it more difficult to detect and analyze.
See also: Go malware has increased by 2000% in recent years
NimzaLoader malware provides access to Windows computers and gives attackers the ability to execute commands. This means that criminals can control the machine, steal sensitive information, or deploy additional malware.
See also: Windows Defender: 12-year-old bug gives hackers administrator privileges
Researchers believe the malware is the work of a group that Proofpoint has dubbed TA800. This group has targeted organizations across multiple industries in North Africa.
The group has also been linked to BazarLoader, a trojan that creates a backdoor on compromised Windows computers and is commonly used to carry out ransomware attacks.
Like BazarLoader, NimzaLoader is distributed via phishing emails that link victims to a fake PDF downloader, which, if executed, will download the malware onto the machine. Phishing emails are usually elaborate and include victims' personal information to make them appear more convincing.
The message template and payload delivery method are consistent with previous TA800 phishing campaigns. For this reason, researchers believe that the NimzaLoader malware likely belongs to this group.

“TA800 has leveraged different and unique malware, and the developers may have chosen to use an unusual programming language, such as Nim, to avoid detection, as reverse engineers may not be familiar with the Nim implementation, and therefore tools and sandboxes may have difficulty analyzing this sample,” said Sherrod DeGrippo, senior director of threat research and detection at Proofpoint.
As phishing is the primary distribution method of NimzaLoader, organizations should protect their network with tools that prevent malicious emails from arriving in the Inbox.
Useful information:Phishing emails: How to recognize them and how to protect yourself?
Organizations should also train employees to recognize phishing emails.
Source: ZDNet
