ATT&CKReferencesPaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023

PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023

Unit 42. (2023, November 21). Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors. Retrieved October 17, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples46

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareBeaverTail

BeaverTail has exfiltrated data collected from local systems.

T1016
System Network Configuration Discovery
MalwareInvisibleFerret

InvisibleFerret has collected the local IP address, and external IP.

T1027.013
Encrypted/Encoded File
MalwareBeaverTail

BeaverTail has obfuscated strings of code with Base64 encoding within the JavaScript version of the malware. BeaverTail has also utilized the open-source tool JavaScript-Obfuscator to obfuscate strings and functions.

T1027.013
Encrypted/Encoded File
MalwareInvisibleFerret

InvisibleFerret has utilized the XOR and Base64 encoding for each of its modules. InvisibleFerret has also obfuscated files with a combination of zlib, Base64 and reverse string order. InvisibleFerret has also utilized the XOR and Base64 encoding some of its Python scripts.

T1033
System Owner/User Discovery
MalwareInvisibleFerret

InvisibleFerret has identified the user’s UUID and username through the "pay" module.

T1036
Masquerading
GroupContagious Interview

Contagious Interview has delivered BeaverTail malware masquerading as legitimate software or applications. Contagious Interview has also delivered malicious payloads masquerading as legitimate software drivers.

T1041
Exfiltration Over C2 Channel
GroupContagious Interview

Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareBeaverTail

BeaverTail has exfiltrated data collected from victim devices to C2 servers.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupContagious Interview

Contagious Interview has exfiltrated victim information using FTP.

T1056
Input Capture
MalwareInvisibleFerret

InvisibleFerret has collected mouse and keyboard events using “pyWinhook”.

T1056.001
Keylogging
MalwareInvisibleFerret

InvisibleFerret has conducted keylogging using the Python project “pyWinHook” and "Pyhook". InvisibleFerret has also captured keylogging thread checks for changes in an active window and key presses.

T1057
Process Discovery
MalwareInvisibleFerret

InvisibleFerret has the capability to query installed programs and running processes. InvisibleFerret has also identified running processes using the Python project “psutil”.

T1059.006
Python
MalwareInvisibleFerret

InvisibleFerret is written in Python and has used Python scripts for execution.

T1059.006
Python
GroupContagious Interview

Contagious Interview has used the Python-based malware such as InvisibleFerret to install and execute Python Packages and Python modules.

T1059.007
JavaScript
MalwareBeaverTail

BeaverTail has executed malicious JavaScript code. BeaverTail has also been compiled with the Qt framework to execute in both Windows and macOS.

T1071.001
Web Protocols
MalwareInvisibleFerret

InvisibleFerret has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareBeaverTail

BeaverTail has used HTTP GET request to download malicious payloads to include InvisibleFerret and HTTP POST to exfiltrate data to C2 infrastructure.

T1082
System Information Discovery
MalwareInvisibleFerret

InvisibleFerret has collected OS type, hostname and system version through the "pay" module. InvisibleFerret has also queried the victim device using Python scripts to obtain the User and Hostname.

T1082
System Information Discovery
MalwareBeaverTail

BeaverTail has been known to collect basic system information. BeaverTail has also collected data to include hostname and current timestamp prior to uploading data to the API endpoint `/uploads` on the C2 server.

T1083
File and Directory Discovery
GroupContagious Interview

Contagious Interview has conducted key word searches within files and directories on a compromised hosts to identify files for exfiltration.

T1083
File and Directory Discovery
MalwareInvisibleFerret

InvisibleFerret has identified specific directories and files for exfiltration using the `ssh_upload` command which contains subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr`, `sfind`. InvisibleFerret also has the capability to scan and upload files of interest from multiple OS systems through the use of scripts that check file names, file extensions, and avoids certain path names. InvisibleFerret has utilized the `findstr` on Windows or the macOS `find` commands to search for files of interest.

T1087.001
Local Account
MalwareInvisibleFerret

InvisibleFerret has queried the victim device using Python scripts to obtain the User and Hostname.

T1095
Non-Application Layer Protocol
MalwareInvisibleFerret

InvisibleFerret has established a connection with the C2 server over TCP traffic. InvisibleFerret has also created a TCP reverse shell communicating via a socket connection over ports 1245, 80, 2245, 3001, and 5000.

T1105
Ingress Tool Transfer
MalwareInvisibleFerret

InvisibleFerret has downloaded “AnyDesk.exe” into the user’s home directory from the C2 server when checks for the service fail to identify its presence in the victim environment. InvisibleFerret has also been configured to download additional payloads using a command which calls to the /bow URI.

T1105
Ingress Tool Transfer
MalwareBeaverTail

BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret.

T1115
Clipboard Data
MalwareInvisibleFerret

InvisibleFerret has stolen data from the clipboard using the Python project “pyperclip”. InvisibleFerret has also captured clipboard contents during copy and paste operations.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareBeaverTail

BeaverTail has been hosted on code repositories and disseminated to victims through NPM packages.

T1204.005
Malicious Library
GroupContagious Interview

Contagious Interview has relied on users to install a malicious library from a code repository to infect the victim's device and has led to additional payload distribution and theft of sensitive data.

T1217
Browser Information Discovery
MalwareBeaverTail

BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets.

T1219
Remote Access Tools
MalwareInvisibleFerret

InvisibleFerret has utilized remote access software including AnyDesk client through the “adc” module. InvisibleFerret has also downloaded the AnyDesk client should it not already exist on the compromised host by searching for `C:/Program Files(x86)/AnyDesk/AnyDesk.exe`.

T1219.002
Remote Desktop Software
GroupContagious Interview

Contagious Interview has downloaded remote management and monitoring software such as “AnyDesk” for post compromise activities.

T1489
Service Stop
MalwareInvisibleFerret

InvisibleFerret has terminated Chrome and Brave browsers using the `taskkill` command on Windows and the `killall` command on other systems such as Linux and macOS. InvisibleFerret has also utilized it’s `ssh_kill` command to terminate Chrome and Brave browser processes.

T1571
Non-Standard Port
MalwareBeaverTail

BeaverTail has communicated with C2 IP addresses over ports 1224 or 1244.

T1583.003
Virtual Private Server
GroupContagious Interview

Contagious Interview has acquired virtual private servers from services such as Stark Industries Solutions and RouterHosting. Contagious Interview has also utilized hosting providers to include Tier[.]Net, Majestic Hosting, Leaseweb Singapore, and Kaopu Cloud.

T1587
Develop Capabilities
GroupContagious Interview

Contagious Interview developed malicious NPM packages for delivery to or retrieval by victims.

T1588.002
Tool
GroupContagious Interview

Contagious Interview has used remote management and monitoring software such as “AnyDesk”.

T1589
Gather Victim Identity Information
GroupContagious Interview

Contagious Interview has researched specific professional groups such as software developers for targeting. Contagious Interview has also researched individuals who work in roles related to cryptocurrency and blockchain technologies.

T1593.001
Social Media
GroupContagious Interview

Contagious Interview had identified and solicited victims through social media such as LinkedIn, X, and Telegram.

T1593.003
Code Repositories
GroupContagious Interview

Contagious Interview had identified and solicited victims through code repositories such as GitHub.

T1608.001
Upload Malware
GroupContagious Interview

Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download.

T1614
System Location Discovery
MalwareInvisibleFerret

InvisibleFerret has collected the internal IP address, IP geolocation information of the infected host and sends the data to a C2 server. InvisibleFerret has also leveraged the “pay” module to obtain region name, country, city, zip code, ISP, latitude and longitude using “http://ip-api.com/json”.

T1657
Financial Theft
GroupContagious Interview

Contagious Interview has stolen cryptocurrency wallet credentials and credit card information utilizing BeaverTail and InvisibleFerret malware.

T1657
Financial Theft
MalwareInvisibleFerret

InvisibleFerret has searched the victim device credentials and files commonly associated with cryptocurrency wallets.

T1657
Financial Theft
MalwareBeaverTail

BeaverTail has searched the victim device for browser extensions commonly associated with cryptocurrency wallets.

T1679
Selective Exclusion
MalwareInvisibleFerret

InvisibleFerret has the capability to scan for file names, file extensions, and avoids pre-designated path names and file types.

T1684.001
Impersonation
GroupContagious Interview

Contagious Interview had impersonated HR hiring personnel through social media, job board notifications, and conducted interviews with victims in order to entice them to download malware disguised as legitimate applications or malicious scripts from code repositories.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.