Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware BeaverTail

BeaverTail

TLP:CLEAR
Family

AI Analysis

· 12 hours ago

Executive Summary

BeaverTail is a multi‑platform malware family that steals browser credentials and downloads further payloads for North Korean actors. Delivered via code repositories or malicious attachments, it operates stealthily across Linux, macOS, and Windows ecosystems. Security teams should block known beacon domains and monitor suspicious outbound traffic to mitigate its impact.

Enhanced Description

BeaverTail is a cross‑platform cyber‑threat that first emerged in 2022 and remains active across Linux, macOS, and Windows. The malware exists in two main codebases: a JavaScript variant primarily distributed through compromised web pages and code repositories, and a C++ variant delivered as a malicious attachment or bundled component. Both variants share the same core objectives—stealing user credentials from installed browsers and acting as a downloader that fetches subsequent payloads to extend the attack chain. Once executed, BeaverTail enumerates locally stored browser profiles (Chrome, Firefox, Edge) to harvest login cookies, autofill data, and HTTP basic authentication tokens. The stolen data is then uploaded to command‑and‑control servers controlled by threat actors affiliated with North Korea, notably DeceptiveDevelopment and Contagious Interview. After exfiltration, the malware connects back to the same C&C infrastructure to download additional modules—ranging from ransomware components to credential‑harvesting DLLs—thereby facilitating a multi‑stage compromise. The attack vector is often stealthy: attackers leverage popular code‑hosting platforms (GitHub, GitLab) and embed BeaverTail within legitimate repositories or malicious script bundles. Attachments disguised as library updates are also used, enabling the malware to bypass traditional scanning when users download or execute the compromised file. Because of its multi‑language nature and distributed delivery methods, detecting BeaverTail requires a combination of signature‑based, behavioral, and network‑based controls. Overall, BeaverTail presents a sophisticated threat that blends credential theft with flexible downloader capabilities, demonstrating an intent to maintain persistence and expand its toolset once initial access is gained.

Key Capabilities

  • Steals login credentials from major web browsers (Chrome, Firefox, Edge)
  • Downloads additional malicious modules as a secondary payload
  • Operates in both JavaScript and C++ variants for cross‑platform coverage
  • Exfiltrates stolen data to command‑and‑control servers linked to North Korean threat actors
  • Distributes via compromised code repository sites and embedded attachments
  • Binds to dynamic IP/URL infrastructure to evade static blocking

ATT&CK Techniques

T1555.003
T1105
T1128

Recommended Actions

  • Implement network segmentation and block outbound connections to known BeaverTail C&C domains/IPs.
  • Deploy anti‑phishing and attachment filtering rules targeting malicious ZIP/EXE files from code‑hosting platforms.
  • Enable browser credential monitoring and enforce multi‑factor authentication to reduce credential compromise impact.
  • Use host‑based endpoint detection capable of spotting runtime JavaScript execution or suspicious binary downloads.
  • Apply the latest OS patches and keep web browsers updated to remove known vulnerabilities exploited by credential theft modules.
  • Maintain a baseline of legitimate network traffic patterns and set up anomaly‑based alerts for outbound data exfiltration to external servers.

Suggested Tags

credential-theft
downloader
cross-platform
state-sponsored
north-korea
malicious-attachment
code-repository-delivery
JavaScript
C++
browser-exfiltration

Confidence Assessment

The assessment is based on multiple vendor reports (Palo Alto, Esentire, ESET, Zscaler) and documented links to North Korean actors, providing high confidence in the core capabilities and delivery methods. However, missing detailed time‑stamps for first and last sightings limit precision on activity windows, and limited public source code leaves gaps regarding low‑level technical implementations such as specific C&C communication protocols.

Description

BeaverTail is a malware that has both a JavaScript and C++ variant. Active since 2022, BeaverTail is capable of stealing logins from browsers and serves as a downloader for second stage payloads. BeaverTail has previously been leveraged by North Korea-affiliated actors identified as DeceptiveDevelopment or Contagious Interview. BeaverTail has been delivered to victims through code repository sites and has been embedded within malicious attachments.(Citation: PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023)(Citation: Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024)(Citation: ESET Contagious Interview BeaverTail InvisibleFerret February 2025)(Citation: Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024)

Details

Type
Malware
Platforms
Linux
Macos
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.