TF-MAL-js.beavertail
📛 Threat Title
Malware family: BeaverTail
Description
ThreatFox malware family `js.beavertail`. Printable name: BeaverTail.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
js.beavertail
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.beavertail
IOC database
- Type
- domain
- Value
js.beavertail- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-js.beavertail
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.beavertail
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
Once executed, the payload retrieves BeaverTail , a JavaScript-based malware traditionally disguised in job-related repositories, but here delivered as compiled binaries via packaging tools like PyInstaller. This modification drastically reduced static detection rates, although network behavior remained detectable.
-
web:attack.mitre.org
BeaverTail BeaverTail is a malware that has both a JavaScript and C++ variant. Active since 2022, BeaverTail is capable of stealing logins from browsers and serves as a downloader for second stage payloads. BeaverTail has previously been leveraged by North Korea-affiliated actors identified as DeceptiveDevelopment or Contagious Interview.
-
web:cyberpress.org
BeaverTail malware - North Korean nation-state operators tracked as Contagious Interview and Famous Chollima have refined their BeaverTail .
-
web:cybersecuritynews.com
A sophisticated North Korean nation-state threat actor campaign has emerged, distributing an evolved variant of the BeaverTail malware through deceptive fake hiring platforms and ClickFix social engineering tactics. This latest campaign, active since May 2025, represents a significant tactical shift as threat actors expand beyond their traditional software developer targets to pursue marketing ...
-
web:gbhackers.com
Tech Note - BeaverTail variant distributed via malicious repositories and ClickFix lure 17 September 2025 - Oliver Smith, GitLab Threat Intelligence We have identified infrastructure distributing BeaverTail and InvisibleFerret malware since at least May 2025, operated by North Korean actors tracked as Contagious Interview and Famous Chollima. The campaign uses ClickFix lures to target ...
-
web:gitlab-com.gitlab.io
Tech Note - BeaverTail variant distributed via malicious repositories and ClickFix lure 17 September 2025 - Oliver Smith, GitLab Threat Intelligence Key Points We've identified infrastructure used to distribute BeaverTail and InvisibleFerret malware variants since at least May 2025. BeaverTail and InvisibleFerret are malware families operated by North Korean nation-state threat actors ...
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Beavertail malware family including references, samples and yara signatures.
-
web:thehackernews.com
DPRK used ClickFix to deliver compiled BeaverTail to crypto marketers; Windows build used password-protected archives, revealing a tactical shift.
-
web:unit42.paloaltonetworks.com
The malware authors compiled BeaverTail variants for both Windows and macOS from the same source code using the Qt programming language. North Korean threat actors are known to conduct financial crimes for funds to support the DPRK regime.
-
web:www.travismathison.com
The adversary uses custom malware families BeaverTail and InvisibleFerret, remote monitoring and management tools (RMMs), and malicious Node.js applications to deliver malware to victims. They also infiltrate corporate environments through malicious insiders, often hired as full-time equivalents directly or via contracting organizations.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.