Executive Summary
BeaverTail is a multi‑platform malware family that steals browser credentials and downloads further payloads for North Korean actors. Delivered via code repositories or malicious attachments, it operates stealthily across Linux, macOS, and Windows ecosystems. Security teams should block known beacon domains and monitor suspicious outbound traffic to mitigate its impact.
Enhanced Description
BeaverTail is a cross‑platform cyber‑threat that first emerged in 2022 and remains active across Linux, macOS, and Windows. The malware exists in two main codebases: a JavaScript variant primarily distributed through compromised web pages and code repositories, and a C++ variant delivered as a malicious attachment or bundled component. Both variants share the same core objectives—stealing user credentials from installed browsers and acting as a downloader that fetches subsequent payloads to extend the attack chain. Once executed, BeaverTail enumerates locally stored browser profiles (Chrome, Firefox, Edge) to harvest login cookies, autofill data, and HTTP basic authentication tokens. The stolen data is then uploaded to command‑and‑control servers controlled by threat actors affiliated with North Korea, notably DeceptiveDevelopment and Contagious Interview. After exfiltration, the malware connects back to the same C&C infrastructure to download additional modules—ranging from ransomware components to credential‑harvesting DLLs—thereby facilitating a multi‑stage compromise. The attack vector is often stealthy: attackers leverage popular code‑hosting platforms (GitHub, GitLab) and embed BeaverTail within legitimate repositories or malicious script bundles. Attachments disguised as library updates are also used, enabling the malware to bypass traditional scanning when users download or execute the compromised file. Because of its multi‑language nature and distributed delivery methods, detecting BeaverTail requires a combination of signature‑based, behavioral, and network‑based controls. Overall, BeaverTail presents a sophisticated threat that blends credential theft with flexible downloader capabilities, demonstrating an intent to maintain persistence and expand its toolset once initial access is gained.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based on multiple vendor reports (Palo Alto, Esentire, ESET, Zscaler) and documented links to North Korean actors, providing high confidence in the core capabilities and delivery methods. However, missing detailed time‑stamps for first and last sightings limit precision on activity windows, and limited public source code leaves gaps regarding low‑level technical implementations such as specific C&C communication protocols.
BeaverTail is a malware that has both a JavaScript and C++ variant. Active since 2022, BeaverTail is capable of stealing logins from browsers and serves as a downloader for second stage payloads. BeaverTail has previously been leveraged by North Korea-affiliated actors identified as DeceptiveDevelopment or Contagious Interview. BeaverTail has been delivered to victims through code repository sites and has been embedded within malicious attachments.(Citation: PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023)(Citation: Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024)(Citation: ESET Contagious Interview BeaverTail InvisibleFerret February 2025)(Citation: Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024)