BeaverTail

MITRE ATT&CK: S1246 View on attack.mitre.org

Aliases: BeaverTail

First seen
2022-01-01 00:00:00
Malware type
credential-stealer, downloader
Family
Malware family
Operating systems
linux, macos, windows
Related IoCs
63 (15 malicious)
Last IoC activity
2026-08-28 16:11:01
Profile updated
2026-07-07 13:14:59

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:kr country_code:us country_code:jp

Context

BeaverTail is a malware that has both a JavaScript and C++ variant. Active since 2022, BeaverTail is capable of stealing logins from browsers and serves as a downloader for second stage payloads. BeaverTail has previously been leveraged by North Korea-affiliated actors identified as DeceptiveDevelopment or Contagious Interview. BeaverTail has been delivered to victims through code repository sites and has been embedded within malicious attachments.

Recent IoC activity

15 malicious indicators in Maltiverse are attributed to BeaverTail (S1246). The 15 most recently updated:

TypeIndicatorUpdatedSources
IP address 45.61.150.67 2026-08-28 4
file sample 74009ad71c2f41ebfe6b76358f0224f814f8dca1167a858538b5e8df8a76b881 2026-08-17 1
file sample 7520924e8d680263216a8eae31e6e2fc4424024ab61d7eb1503b663cb82811d2 2026-08-03 1
file sample downx64.sh 2026-08-01 2
file sample 05ae07783d30b37aa5f0ffff86adde57d0d497fe915537a3fc010230b54e1ee8 2026-08-01 1
file sample nvidiasdk.exe 2026-08-01 2
file sample update.vbs 2026-08-01 2
file sample linux_beavertail_clickfix_second_stage 2026-08-01 2
file sample linux_beavertail_clickfix_first_stage 2026-08-01 2
file sample nvidia.tar.gz 2026-08-01 2
file sample x64nvidia 2026-08-01 2
file sample payuniversal2 2026-08-01 2
file sample 4a1588e27a3f322e94e490173fe2bfa8d6e2f407b81a77af8787619b0d3d10bd 2026-08-01 1
file sample c3921fef70e1895559fe0caea0ea678e8df4e4d3b65dcde33103379b4dbdf99a 2026-07-18 1
hostname lianxinxiao.com 2026-07-15 1

Detection coverage

  • 315 Sigma rules

Malware & tools used

  • Web Protocols (attack-pattern)
  • JavaScript (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Log Enumeration (attack-pattern)
  • Compromise Software Dependencies and Development Tools (attack-pattern)
  • Browser Information Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Data from Local System (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Credentials from Password Stores (attack-pattern)
  • Malicious File (attack-pattern)
  • Junk Data (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Masquerading (attack-pattern)
  • File Deletion (attack-pattern)
  • Financial Theft (attack-pattern)
  • Keychain (attack-pattern)

Used by threat actors

Reports & references

  • Palo Alto Unit 42 — Two Campaigns By North Korea Bad Actors Target Job Hunters (report)
  • zscaler.com — Pyongyang Your Payroll Rise North Korean Remote Workers West (report)
  • Palo Alto Unit 42 — North Korean Threat Actors Lure Tech Job Seekers As Fake Recruiters (report)
  • esentire.com — Bored Beavertail Invisibleferret Yacht Club A Lazarus Lure Pt 2 (report)
  • ESET — Deceptivedevelopment Targets Freelance Developers (report)
  • nimanthadeshappriya.com — From Colombo To Pyongyang (report)
  • blog.nviso.eu — Contagious Interview Actors Now Utilize Json Storage Services For Malware Delivery (report)
  • gitlab-com.gitlab.io — North Korean Malware Sept 2025 (report)
  • group-ib.com — Apt Lazarus Python Scripts (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Beavertail (report)
  • MITRE ATT&CK — S1246 (report)

External references