BeaverTail is a Node.js-based malware family used as an initial-stage stealer and loader in the DPRK-linked Contagious Interview activity cluster, including operations associated with Lazarus Group and tracking names such as Famous Chollima or WaterPlum. It is primarily delivered through social-engineering lures aimed at software developers, Web3 personnel, cryptocurrency organizations, and in some cases marketing or trading roles. Common delivery patterns include trojanized coding challenges, malicious npm dependencies and packages, weaponized Git repositories, fake job interview projects, VS Code task abuse, ClickFix-style instructions, and fake desktop applications built for cross-platform execution.
BeaverTail is designed to rapidly collect host and browser data and to facilitate follow-on compromise. Observed functionality includes theft of passwords saved in web browsers, browser profile data, session-related browser data, cryptocurrency wallet extension data, and other sensitive developer or financial artifacts. Variants have also searched for and exfiltrated files likely to contain secrets such as environment files, wallet material, credentials, and project-related data. Some samples include broader backdoor-like behavior such as host fingerprinting, system information collection, remote command execution support, file search and upload, and communication with attacker-controlled services over HTTP or socket-based channels.
A defining role of BeaverTail is staging additional malware. It has repeatedly been observed downloading and executing the Python-based InvisibleFerret backdoor, and in later Contagious Interview operations it has also appeared alongside or as part of delivery chains involving OtterCookie and other follow-on tooling. On Windows, some variants download or bundle a Python runtime to ensure subsequent payload execution even when Python is not already installed. Cross-platform targeting is well established, with Windows, macOS, and Linux variants documented, including JavaScript implementations and compiled forms adapted to different victim environments.
Operationally, BeaverTail is strongly associated with financially motivated and espionage-oriented intrusions against developer ecosystems, especially where browser sessions, source code, cloud credentials, and cryptocurrency assets are present. Its recurring use in fake recruitment and collaboration scenarios, combined with rapid data theft and second-stage deployment, makes it a key entry component in DPRK developer-targeting campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Contagious Interview campaign conducted by the Lazarus Group continues to expand its capabilities. We have observed an exponential evolution in the delivery mechanisms for the campaign’s main payloads: BeaverTail, InvisibleFerret, and OtterCookie.
They have been using malware called BeaverTail or InvisibleFerret in Contagious Interview campaign since around 2023, they started using new malware since September 2024.
The PolinRider threat group was first detected this year when cybersecurity analysts identified hundreds of GitHub repositories with hidden JavaScript code that downloads an updated version of the BeaverTail malware.
Instructional videos have also been found with what it looks like non-native English text, detailing how to set up a Beavertail malware command-and-control server and how to crack cryptocurrency wallet passwords.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Analiza deljenega projekta je pokazala, da gre za Node.js Package Manager (NPM) paket. Projekt vsebuje tudi navodila za gradnjo in zagon programa, katera izvedejo tudi zlonamerno kodo.
T1566 Phishing ... The Threat Actor approaches their victims via LinkedIn and poses as a potential business partner.
T1059 Command and Scripting Interpreter Multiple stages rely on Scripting Interpreters like JavaScript, PowerShell and Python.
na Windows sistemih najprej namesti Python 3.11 okolje... z orodjem curl prenese ZIP arhiv ... Ta arhiv nato z orodjem tar razširi
The update.vbs script is a VisualBasic script that performs two actions ... Executes the nvidiasdk.exe executable, which contains BeaverTail.
Datoteka server.js ... s funkcijo require naloži dodatne module... v modulu userRoutes se pa skriva začetek zlonamerne kode.
koda pa je bila verjetno zamaskirana oz. obfuskirana z uporabo odprto-kodnega obfuskatorja javascript-obfuscator
napadalci lažno predstavljajo kot iskalci zaposlitve ali pa želijo kakšno drugo sodelovanje z neko organizacijo
z orodjem curl prenese ZIP arhiv ... Ta arhiv nato z orodjem tar razširi
These guardrails delay automated identification and linking of the threat actor’s infrastructure and reduce their footprint in security sandboxes.
If a request is made without a specific user agent, the threat actor’s service responds with a decoy payload... These guardrails delay automated identification and linking of the threat actor’s infrastructure and reduce their footprint in security sandboxes.
krade gesla in kreditne kartice shranjenih v spletnih brskalnikih
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
The malware establishes persistent command-and-control communication, exfiltrates system information... including hostnames, MAC addresses, and OS details every five seconds.
najprej poskusi poslati nekaj osnovnih informacij o sistemu na t.i. C2 strežnik
These guardrails delay automated identification and linking of the threat actor’s infrastructure and reduce their footprint in security sandboxes.
If a request is made without a specific user agent, the threat actor’s service responds with a decoy payload... These guardrails delay automated identification and linking of the threat actor’s infrastructure and reduce their footprint in security sandboxes.
407 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
181 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as broader background on developer-targeting malware, not as a payload explicitly used in this ClickOnce chain.
Named as a loader tool associated with the malware/tooling discussed in the Contagious Interview campaign.
Referenced as a related developer-targeting malware family previously used in fake-project delivery chains.
BeaverTail3
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.