BeaverTail is a Node.js-based malware family closely associated with the DPRK-linked Contagious Interview activity cluster, including operators tracked as Lazarus Group, Famous Chollima, and WaterPlum in public reporting. It is typically used as an early-stage payload in social-engineering campaigns that target software developers, Web3 personnel, cryptocurrency traders, and other technology-focused victims through fake job interviews, trojanized coding challenges, malicious repositories, poisoned package dependencies, and related developer workflow lures. More recent operations also show adaptation to less technical targets through compiled variants and ClickFix-style execution prompts.
BeaverTail primarily functions as an infostealer and loader. Its collection behavior includes theft of browser-saved credentials, browser session and autofill data, cryptocurrency wallet extension data, and other host information. Multiple reports also describe theft of files related to wallets, secrets, source code, and developer environments. On some platforms and variants, BeaverTail gathers system metadata such as hostname, username, operating system details, network identifiers, and geolocation-related information before transmitting it to command-and-control infrastructure.
A defining role of BeaverTail is staging follow-on malware, most notably the Python-based InvisibleFerret, and in some campaigns other payloads such as OtterCookie or broader post-compromise frameworks. Delivery chains commonly use obfuscated JavaScript embedded in project files, malicious package logic, hidden code in repositories, or VS Code task automation that executes when a victim opens or runs a project. Some variants create hidden directories masquerading as development tooling components, download bootstrap scripts, ensure Node.js or Python runtime availability, and then retrieve additional payloads. Public reporting also describes BeaverTail variants delivered through fake Electron or Qt applications and compiled binaries for Windows and macOS.
Operationally, BeaverTail has been used in campaigns focused on cryptocurrency theft, credential harvesting, and longer-term espionage against developer and blockchain ecosystems. It has targeted browser extensions associated with numerous cryptocurrency wallets and has been observed exfiltrating sensitive data before later-stage malware is blocked, making it dangerous even as a first-stage implant. In several intrusion chains, BeaverTail also includes backdoor-like functions such as remote command execution support, file discovery, and additional payload retrieval, though its most consistent role is initial theft and staging for subsequent compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Contagious Interview campaign conducted by the Lazarus Group continues to expand its capabilities. We have observed an exponential evolution in the delivery mechanisms for the campaign’s main payloads: BeaverTail, InvisibleFerret, and OtterCookie.
They have been using malware called BeaverTail or InvisibleFerret in Contagious Interview campaign since around 2023, they started using new malware since September 2024.
The PolinRider threat group was first detected this year when cybersecurity analysts identified hundreds of GitHub repositories with hidden JavaScript code that downloads an updated version of the BeaverTail malware.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Analiza deljenega projekta je pokazala, da gre za Node.js Package Manager (NPM) paket. Projekt vsebuje tudi navodila za gradnjo in zagon programa, katera izvedejo tudi zlonamerno kodo.
T1566 Phishing ... The Threat Actor approaches their victims via LinkedIn and poses as a potential business partner.
T1059 Command and Scripting Interpreter Multiple stages rely on Scripting Interpreters like JavaScript, PowerShell and Python.
na Windows sistemih najprej namesti Python 3.11 okolje... z orodjem curl prenese ZIP arhiv ... Ta arhiv nato z orodjem tar razširi
The update.vbs script is a VisualBasic script that performs two actions ... Executes the nvidiasdk.exe executable, which contains BeaverTail.
Datoteka server.js ... s funkcijo require naloži dodatne module... v modulu userRoutes se pa skriva začetek zlonamerne kode.
koda pa je bila verjetno zamaskirana oz. obfuskirana z uporabo odprto-kodnega obfuskatorja javascript-obfuscator
napadalci lažno predstavljajo kot iskalci zaposlitve ali pa želijo kakšno drugo sodelovanje z neko organizacijo
z orodjem curl prenese ZIP arhiv ... Ta arhiv nato z orodjem tar razširi
These guardrails delay automated identification and linking of the threat actor’s infrastructure and reduce their footprint in security sandboxes.
If a request is made without a specific user agent, the threat actor’s service responds with a decoy payload... These guardrails delay automated identification and linking of the threat actor’s infrastructure and reduce their footprint in security sandboxes.
krade gesla in kreditne kartice shranjenih v spletnih brskalnikih
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
The malware establishes persistent command-and-control communication, exfiltrates system information... including hostnames, MAC addresses, and OS details every five seconds.
najprej poskusi poslati nekaj osnovnih informacij o sistemu na t.i. C2 strežnik
These guardrails delay automated identification and linking of the threat actor’s infrastructure and reduce their footprint in security sandboxes.
If a request is made without a specific user agent, the threat actor’s service responds with a decoy payload... These guardrails delay automated identification and linking of the threat actor’s infrastructure and reduce their footprint in security sandboxes.
407 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
182 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
the coding challenge is laced with malware and will trigger something nasty like InvisibleFerret, BeaverTail, OtterCookie, or one of the many other malware strains from our friends in boring Korea.
Referenced only as broader background on developer-targeting malware, not as a payload explicitly used in this ClickOnce chain.
Named as a loader tool associated with the malware/tooling discussed in the Contagious Interview campaign.
Referenced as a related developer-targeting malware family previously used in fake-project delivery chains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.