Skip to content

BeaverTail

BeaverTail is a Node.js-based first-stage loader and information stealer used in the DPRK-aligned Contagious Interview activity cluster, commonly associated with Lazarus-linked operators including WaterPlum/Famous Chollima.

Profile source: Mallory opens in a new tab

BeaverTail

Family profile

BeaverTail is a Node.js-based first-stage loader and information stealer used in the DPRK-aligned Contagious Interview activity cluster, commonly associated with Lazarus-linked operators including WaterPlum/Famous Chollima. It is delivered through social-engineering campaigns that impersonate recruiters, job candidates, or business contacts and provide trojanized coding challenges, malicious repositories, developer projects, or ClickFix instructions. The activity primarily targets software developers, Web3 and cryptocurrency professionals, and organizations whose endpoints contain source code, cloud credentials, browser sessions, cryptocurrency wallets, and developer secrets.

BeaverTail fingerprints infected systems and steals browser-stored credentials, browser data, session information, and cryptocurrency-wallet extension data. Variants collect sensitive files such as environment files, keys, configuration material, wallet-related data, and developer artifacts, then exfiltrate them to attacker-controlled infrastructure. BeaverTail commonly downloads and launches additional payloads, particularly the Python-based InvisibleFerret backdoor, and some components support remote shell execution, file discovery and transfer, process control, and retrieval of further JavaScript payloads. Campaigns employ obfuscation, staged payload retrieval, execution through development-tool features, and environment-aware delivery controls to reduce static-analysis visibility. BeaverTail has been observed on Windows, macOS, and Linux.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Post Exploitation
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 9, 2026
Last activity
Sep 14, 2026
Feed role
C2 / Distribution
Host form
1 IP / 10 hostnames

Leading locations

  • US9
  • CA1
  • FR1

Leading providers

  • Amazon.com, Inc.8
  • DigitalOcean, LLC1
  • OVH SAS1
  • Team Internet AG1

Infrastructure traits

  • Hosting 11
  • Anycast 8

Reported operators

Threat actors

8 named in public reporting
Lazarus

Lazarus using LLMs to polymorph BeaverTail and InvisibleFerret for every single target.

Contagious Interview

They have been using malware called BeaverTail or InvisibleFerret in Contagious Interview campaign since around 2023, they started using new malware since September 2024.

PolinRider

The PolinRider threat group was first detected this year when cybersecurity analysts identified hundreds of GitHub repositories with hidden JavaScript code that downloads an updated version of the BeaverTail malware.

CL-STA-0240

The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.

TraderTraitor

The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.

HexagonalRodent

The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.

Nickel Alley

The code in index.js implements the Node.js fetch API to send an HTTP request to that URL and retrieve BeaverTail malware.

DPRK

"Tech Note - BeaverTail variant distributed via malicious repositories and ClickFix lure... DPRK’s BeaverTail malware"

MITRE ATT&CK

BeaverTail in ATT&CK

99 distinct techniques

Techniques

99 techniques
T1566 Phishing T1027 Obfuscated Files or Information T1555.003 Credentials from Web Browsers T1005 Data from Local System T1041 Exfiltration Over C2 Channel T1218 System Binary Proxy Execution T1555 Credentials from Password Stores T1059.004 Unix Shell T1082 System Information Discovery T1059.007 JavaScript T1105 Ingress Tool Transfer T1204 User Execution T1195 Supply Chain Compromise T1566.003 Spearphishing via Service T1071.001 Web Protocols T1036 Masquerading T1059 Command and Scripting Interpreter T1608 Stage Capabilities T1649 Steal or Forge Authentication Certificates T1033 System Owner/User Discovery T1497.003 Time Based Checks T1059.005 Visual Basic T1497 Virtualization/Sandbox Evasion T1622 Debugger Evasion T1497.001 System Checks T1566.002 Spearphishing Link T1560 Archive Collected Data T1204.002 Malicious File T1656 Impersonation T1027.003 Steganography T1036.005 Match Legitimate Resource Name or Location T1102 Web Service T1140 Deobfuscate/Decode Files or Information T1102.001 Dead Drop Resolver T1053 Scheduled Task/Job T1057 Process Discovery T1195.001 Compromise Software Dependencies and Development Tools T1571 Non-Standard Port T1071.002 File Transfer Protocols T1199 Trusted Relationship T1083 File and Directory Discovery T1518 Software Discovery T1195.002 Compromise Software Supply Chain T1620 Reflective Code Loading T1564.003 Hidden Window T1573 Encrypted Channel T1505 Server Software Component T1070 Indicator Removal T1574 Hijack Execution Flow T1189 Drive-by Compromise T1583.001 Domains T1071 Application Layer Protocol T1059.006 Python T1555.001 Keychain T1119 Automated Collection T1657 Financial Theft T1564.001 Hidden Files and Directories T1124 System Time Discovery T1552.001 Credentials In Files T1127 Trusted Developer Utilities Proxy Execution T1027.007 Dynamic API Resolution T1176 Software Extensions T1070.004 File Deletion T1074 Data Staged T1608.001 Upload Malware T1027.013 Encrypted/Encoded File T1546.016 Installer Packages T1217 Browser Information Discovery T1552 Unsecured Credentials T1564 Hide Artifacts T1546 Event Triggered Execution T1059.003 Windows Command Shell T1056.001 Keylogging T1048 Exfiltration Over Alternative Protocol T1539 Steal Web Session Cookie T1090.002 External Proxy T1586 Compromise Accounts T1587.001 Malware T1585 Establish Accounts T1547.009 Shortcut Modification T1547.001 Registry Run Keys / Startup Folder T1598 Phishing for Information T1588.001 Malware T1568 Dynamic Resolution T1078 Valid Accounts T1203 Exploitation for Client Execution T1204.001 Malicious Link T1589 Gather Victim Identity Information T1566.001 Spearphishing Attachment T1219 Remote Access Tools T1120 Peripheral Device Discovery T1053.005 Scheduled Task T1055 Process Injection T1547 Boot or Logon Autostart Execution T1560.001 Archive via Utility T1001.001 Junk Data T1074.001 Local Data Staging T1654 Log Enumeration T1567 Exfiltration Over Web Service

Reporting

Research mentioning BeaverTail

Aug 11
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.

Jul 24
Security Online Info

Contagious Interview Hides Malware in Coding Tests

Elastic Security Labs reported a Contagious Interview intrusion tied to a DPRK-aligned threat cluster after suspicious activity targeted Elastic’s community Slack workspace. Using a fake recruiter persona named Maxwell, the operator posted a fraudulent job opportunity and coding challenge that directed victims to trojanized Next.js e-commerce repositories. The malicious code hid payload components inside SVG image files using steganography, embedding Base64 fragments in flag images that were reassembled by serverValidation.js and executed with eval() when the local development server started. The campaign matches the broader Contagious Interview tradecraft tracked in MITRE ATT&CK as G1052, which relies on fake hiring outreach, code-repository lures, and social engineering to infect developers across Windows, macOS, and Linux. Elastic said the infection chain deployed a browser credential and crypto-wallet stealer, a file stealer, a persistent Socket.IO RAT, and a clipboard stealer capable of fetching Windows PE payloads, while code similarities to OTTERCOOKIE and infrastructure overlaps previously documented by JFrog reinforced the attribution. MITRE also associates the cluster with malware such as BeaverTail and InvisibleFerret, along with credential theft, financial theft, persistence through platform-specific startup mechanisms, and exfiltration over C2 and cloud or messaging services.

Jul 20
Cyber Security News

North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers

Jul 20
Gurucul Threat Research

New North Korean Campaign Uses Fake Coding Interviews to Steal Developer Credentials | Community Portal | Gurucul

Jul 18
Cyberveille

Campagne Contagious Interview : malware DPRK caché dans des SVG via stéganographie | CyberVeille

Jul 15
Gurucul Threat Research

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | Community Portal | Gurucul

Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.

Jul 14
Trojan Killer News

Artlist ClickFix Page Dropped a Native Windows RAT

Jul 14
Infostealers Com Infostealers

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | InfoStealers

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.