Multiple public repositories and technical blogs show Nim being actively used to build offensive tooling for Windows and Linux, including malware loaders, command-and-control agents, and post-exploitation utilities. GitHub projects such as OffensiveNim, Nimbo-C2, PichichiH0ll0wer, and NimBlackout document capabilities including shellcode execution, process hollowing, token impersonation, credential dumping, in-memory PowerShell execution, encrypted HTTP C2, Linux memfd loading, and BYOVD-based attempts to disable AV/EDR. Several projects also emphasize evasion tradecraft such as AMSI and ETW patching, syscall-based injection, anti-debugging, obfuscated sleep, reflective loading, and reducing static imports to lower detection.
Separate malware-development walkthroughs further demonstrate Nim-based payload encryption and execution techniques using RC4, RC5, and TEA, as well as callback abuse through EnumDesktopsA and remote process injection into mspaint.exe. The examples rely on common Windows APIs for memory allocation, payload staging, and thread creation, and were presented as proof-of-concept code compiled with Nim and MinGW for x64 Windows targets. Taken together, the material shows Nim maturing from a niche language into a practical platform for malware authors and red-team developers seeking native binaries, cross-compilation, and flexible access to low-level Windows functionality.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository published Nimbo-C2, a lightweight command-and-control framework with a Nim-based Windows and Linux agent and Python server components, supporting capabilities such as in-memory PowerShell, shellcode injection, persistence, token impersonation, and credential dumping.
A GitHub repository published PichichiH0ll0wer, a Nim-based process hollowing loader for x64 PE payloads supporting EXE and DLL output, encrypted and compressed payloads, anti-debugging, and multiple hollowing methods including direct and indirect syscalls.
A technical blog post published a Nim proof of concept that pads, encrypts, and decrypts an embedded shellcode payload with TEA, verifies the decrypted bytes, and executes the payload through EnumDesktopsA on Windows.
A technical blog post published a Nim proof of concept that encrypts embedded shellcode with RC5, decrypts it, and executes it from RWX memory via EnumDesktopsA on Windows 10 22H2 x64.
A technical blog post published a Nim example that allocates shellcode with VirtualAlloc, copies it with RtlMoveMemory, and executes it in memory by passing it as an EnumDesktopsA callback on Windows 11.
A technical blog post published a Nim malware proof of concept that encrypts a payload with RC4, decrypts it, and injects it into a newly started mspaint.exe process using OpenProcess, VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread.
A GitHub repository named OffensiveNim was published describing experiments in weaponizing the Nim language for offensive operations, including malware, implants, shellcode execution, injection, AMSI/ETW bypass, credential access, and evasion tradecraft.
The NimBlackout GitHub repository showed updates to README.md and NimBlackout.nim for a Nim proof of concept that uses the gmer/Blackout.sys vulnerable driver to disable AV/EDR processes via a BYOVD technique.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
9 references tracked. Mallory keeps watching after this page renders.
nim-lang.org
Open sourcegithub.com
Open sourcegithub.com
Open sourcecocomelonc.github.io
Open sourcecocomelonc.github.io
Open sourcecocomelonc.github.io
Open sourcecocomelonc.github.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.