Netskope Threat Labs

BeaverTail

ATP Sandbox Adv. HeuristicsAV

BeaverTail is malware associated with North Korean threat actors that has targeted employees of aerospace and other technology organizations through fake recruiter job offers. The infection chain typically begins with a fraudulent coding interview that persuades the victim to run a project downloaded from a fake repository, which loads a JavaScript or Python downloader. That downloader steals browser credentials and installs follow on tools, including the InvisibleFerret backdoor, to maintain access to the victim's systems.

First seen
February 2024
Last seen
October 2026
Beavertail

23 techniques across 9 tactics.

TA0001 Initial Access

  • T1195Supply Chain Compromise
    • T1195.001Compromise Software Dependencies and Development Tools

TA0002 Execution

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1124System Time Discovery
  • T1217Browser Information Discovery
  • T1654Log Enumeration

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel

TA0040 Impact

Alert Name
Gen:Variant.Trojan.MAC.BeaverTail.1
MacOS.Trojan.BeaverTail
Script-JS.Dropper.BeaverTail
Script-JS.Trojan.Beavertail
Script-JS.Trojan.BeaverTail
Script-Python.Trojan.BeaverTail
Trojan.BeaverTail.3
Trojan.JS.BeaverTail.1
Trojan.JS.BeaverTail.3
Trojan.MAC.BeaverTail.2