BeaverTail is a Node.js-based malware family associated with the DPRK-linked Contagious Interview activity cluster, including reporting that ties its use to Lazarus Group and related tracking names such as Famous Chollima and WaterPlum. It is commonly used as an early-stage payload in social-engineering operations that target software developers, Web3 organizations, cryptocurrency users, and, in later variants, some marketing and trading roles. Typical lures involve fake job interviews, trojanized coding challenges, malicious repositories, weaponized npm packages, and ClickFix-style execution prompts. BeaverTail has also appeared in fake Electron- and Qt-based applications and in supply-chain compromises involving malicious dependencies, injected project files, and VS Code task automation.
Functionally, BeaverTail acts as both an infostealer and a loader. It fingerprints the victim environment, collects host information, steals passwords and other browser-stored data, and targets cryptocurrency wallet browser extensions for theft of wallet-related material. Reported variants also collect browser session-related data, browsing artifacts, and files matching sensitive patterns such as secrets, wallet material, and development credentials. On some platforms it exfiltrates browser extension data and browser credential stores directly; on Windows it may additionally fetch a bundled Python environment to ensure execution of follow-on payloads.
A core role of BeaverTail is staging additional malware, most notably the Python-based InvisibleFerret backdoor family, and in some campaigns it has been part of broader multi-stage chains involving OtterCookie or Tsunami-related tooling. Delivery and execution methods have evolved over time and include obfuscated JavaScript embedded in project files, remote payload retrieval with runtime execution, token-gated content delivery, error-path execution tricks, compiled platform-specific variants, and automatic execution through development tooling such as VS Code folder-open tasks or Next.js startup logic. Across campaigns, BeaverTail has been used to rapidly steal credentials, wallet data, and developer-sensitive information before handing off to later-stage implants that expand remote access and persistence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Contagious Interview campaign conducted by the Lazarus Group continues to expand its capabilities. We have observed an exponential evolution in the delivery mechanisms for the campaign’s main payloads: BeaverTail, InvisibleFerret, and OtterCookie.
They have been using malware called BeaverTail or InvisibleFerret in Contagious Interview campaign since around 2023, they started using new malware since September 2024.
The PolinRider threat group was first detected this year when cybersecurity analysts identified hundreds of GitHub repositories with hidden JavaScript code that downloads an updated version of the BeaverTail malware.
Instructional videos have also been found with what it looks like non-native English text, detailing how to set up a Beavertail malware command-and-control server and how to crack cryptocurrency wallet passwords.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Analiza deljenega projekta je pokazala, da gre za Node.js Package Manager (NPM) paket. Projekt vsebuje tudi navodila za gradnjo in zagon programa, katera izvedejo tudi zlonamerno kodo.
T1566 Phishing ... The Threat Actor approaches their victims via LinkedIn and poses as a potential business partner.
T1059 Command and Scripting Interpreter Multiple stages rely on Scripting Interpreters like JavaScript, PowerShell and Python.
na Windows sistemih najprej namesti Python 3.11 okolje... z orodjem curl prenese ZIP arhiv ... Ta arhiv nato z orodjem tar razširi
The update.vbs script is a VisualBasic script that performs two actions ... Executes the nvidiasdk.exe executable, which contains BeaverTail.
Datoteka server.js ... s funkcijo require naloži dodatne module... v modulu userRoutes se pa skriva začetek zlonamerne kode.
koda pa je bila verjetno zamaskirana oz. obfuskirana z uporabo odprto-kodnega obfuskatorja javascript-obfuscator
napadalci lažno predstavljajo kot iskalci zaposlitve ali pa želijo kakšno drugo sodelovanje z neko organizacijo
z orodjem curl prenese ZIP arhiv ... Ta arhiv nato z orodjem tar razširi
These guardrails delay automated identification and linking of the threat actor’s infrastructure and reduce their footprint in security sandboxes.
If a request is made without a specific user agent, the threat actor’s service responds with a decoy payload... These guardrails delay automated identification and linking of the threat actor’s infrastructure and reduce their footprint in security sandboxes.
krade gesla in kreditne kartice shranjenih v spletnih brskalnikih
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
The malware establishes persistent command-and-control communication, exfiltrates system information... including hostnames, MAC addresses, and OS details every five seconds.
najprej poskusi poslati nekaj osnovnih informacij o sistemu na t.i. C2 strežnik
These guardrails delay automated identification and linking of the threat actor’s infrastructure and reduce their footprint in security sandboxes.
If a request is made without a specific user agent, the threat actor’s service responds with a decoy payload... These guardrails delay automated identification and linking of the threat actor’s infrastructure and reduce their footprint in security sandboxes.
407 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
181 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as broader background on developer-targeting malware, not as a payload explicitly used in this ClickOnce chain.
Named as a loader tool associated with the malware/tooling discussed in the Contagious Interview campaign.
Referenced as a related developer-targeting malware family previously used in fake-project delivery chains.
BeaverTail3
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.