BeaverTail
MITRE ATT&CK: S1246 View on attack.mitre.org
Aliases: BeaverTail
- First seen
- 2022-01-01 00:00:00
- Malware type
- credential-stealer, downloader
- Family
- Malware family
- Operating systems
- linux, macos, windows
- Related IoCs
- 63 (15 malicious)
- Last IoC activity
- 2026-08-28 16:11:01
- Profile updated
- 2026-07-07 13:14:59
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:kr country_code:us country_code:jp
Context
BeaverTail is a malware that has both a JavaScript and C++ variant. Active since 2022, BeaverTail is capable of stealing logins from browsers and serves as a downloader for second stage payloads. BeaverTail has previously been leveraged by North Korea-affiliated actors identified as DeceptiveDevelopment or Contagious Interview. BeaverTail has been delivered to victims through code repository sites and has been embedded within malicious attachments.
Recent IoC activity
15 malicious indicators in Maltiverse are attributed to BeaverTail (S1246). The 15 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| IP address | 45.61.150.67 | 2026-08-28 | 4 |
| file sample | 74009ad71c2f41ebfe6b76358f0224f814f8dca1167a858538b5e8df8a76b881 | 2026-08-17 | 1 |
| file sample | 7520924e8d680263216a8eae31e6e2fc4424024ab61d7eb1503b663cb82811d2 | 2026-08-03 | 1 |
| file sample | downx64.sh | 2026-08-01 | 2 |
| file sample | 05ae07783d30b37aa5f0ffff86adde57d0d497fe915537a3fc010230b54e1ee8 | 2026-08-01 | 1 |
| file sample | nvidiasdk.exe | 2026-08-01 | 2 |
| file sample | update.vbs | 2026-08-01 | 2 |
| file sample | linux_beavertail_clickfix_second_stage | 2026-08-01 | 2 |
| file sample | linux_beavertail_clickfix_first_stage | 2026-08-01 | 2 |
| file sample | nvidia.tar.gz | 2026-08-01 | 2 |
| file sample | x64nvidia | 2026-08-01 | 2 |
| file sample | payuniversal2 | 2026-08-01 | 2 |
| file sample | 4a1588e27a3f322e94e490173fe2bfa8d6e2f407b81a77af8787619b0d3d10bd | 2026-08-01 | 1 |
| file sample | c3921fef70e1895559fe0caea0ea678e8df4e4d3b65dcde33103379b4dbdf99a | 2026-07-18 | 1 |
| hostname | lianxinxiao.com | 2026-07-15 | 1 |
Detection coverage
- 315 Sigma rules
Malware & tools used
- Web Protocols (attack-pattern)
- JavaScript (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Log Enumeration (attack-pattern)
- Compromise Software Dependencies and Development Tools (attack-pattern)
- Browser Information Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Local Data Staging (attack-pattern)
- Archive via Utility (attack-pattern)
- Data from Local System (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- System Time Discovery (attack-pattern)
- Non-Standard Port (attack-pattern)
- Credentials from Password Stores (attack-pattern)
- Malicious File (attack-pattern)
- Junk Data (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Masquerading (attack-pattern)
- File Deletion (attack-pattern)
- Financial Theft (attack-pattern)
- Keychain (attack-pattern)
Used by threat actors
- Contagious Interview (threat-actor)
Reports & references
- Palo Alto Unit 42 — Two Campaigns By North Korea Bad Actors Target Job Hunters (report)
- zscaler.com — Pyongyang Your Payroll Rise North Korean Remote Workers West (report)
- Palo Alto Unit 42 — North Korean Threat Actors Lure Tech Job Seekers As Fake Recruiters (report)
- esentire.com — Bored Beavertail Invisibleferret Yacht Club A Lazarus Lure Pt 2 (report)
- ESET — Deceptivedevelopment Targets Freelance Developers (report)
- nimanthadeshappriya.com — From Colombo To Pyongyang (report)
- blog.nviso.eu — Contagious Interview Actors Now Utilize Json Storage Services For Malware Delivery (report)
- gitlab-com.gitlab.io — North Korean Malware Sept 2025 (report)
- group-ib.com — Apt Lazarus Python Scripts (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Beavertail (report)
- MITRE ATT&CK — S1246 (report)
External references
- mitre-attack — S1246
- Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024
- ESET Contagious Interview BeaverTail InvisibleFerret February 2025
- Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024
- PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy