Description
BeaverTail is malware associated with North Korean threat actors that has targeted employees of aerospace and other technology organizations through fake recruiter job offers. The infection chain typically begins with a fraudulent coding interview that persuades the victim to run a project downloaded from a fake repository, which loads a JavaScript or Python downloader. That downloader steals browser credentials and installs follow on tools, including the InvisibleFerret backdoor, to maintain access to the victim's systems.
Stats
- First seen
- February 2024
- Last seen
- October 2026
Also known as
Beavertail
MITRE ATT&CK techniques
23 techniques across 9 tactics.
Associated groups
Alert name variants
| Alert Name |
|---|
| Gen:Variant.Trojan.MAC.BeaverTail.1 |
| MacOS.Trojan.BeaverTail |
| Script-JS.Dropper.BeaverTail |
| Script-JS.Trojan.Beavertail |
| Script-JS.Trojan.BeaverTail |
| Script-Python.Trojan.BeaverTail |
| Trojan.BeaverTail.3 |
| Trojan.JS.BeaverTail.1 |
| Trojan.JS.BeaverTail.3 |
| Trojan.MAC.BeaverTail.2 |