ATT&CKSoftwareBeaverTail

BeaverTail

S1246

Malware.View on attack.mitre.org

About this malware

BeaverTail is a malware that has both a JavaScript and C++ variant. Active since 2022, BeaverTail is capable of stealing logins from browsers and serves as a downloader for second stage payloads. BeaverTail has previously been leveraged by North Korea-affiliated actors identified as DeceptiveDevelopment or Contagious Interview. BeaverTail has been delivered to victims through code repository sites and has been embedded within malicious attachments.

Techniques used23

Procedure examples23

TechniqueProcedure example
T1001.001
Junk Data

BeaverTail has added junk data or a dummy character prepended to a string to hamper decoding attempts.

T1005
Data from Local System

BeaverTail has exfiltrated data collected from local systems.

T1027.013
Encrypted/Encoded File

BeaverTail has obfuscated strings of code with Base64 encoding within the JavaScript version of the malware. BeaverTail has also utilized the open-source tool JavaScript-Obfuscator to obfuscate strings and functions.

T1036
Masquerading

BeaverTail has masqueraded as MiroTalk installation packages: “MiroTalk.dmg” for macOS and “MiroTalk.msi” for Windows, and has included login GUIs with MiroTalk themes.

T1041
Exfiltration Over C2 Channel

BeaverTail has exfiltrated data collected from victim devices to C2 servers.

T1059.007
JavaScript

BeaverTail has executed malicious JavaScript code. BeaverTail has also been compiled with the Qt framework to execute in both Windows and macOS.

T1070.004
File Deletion

BeaverTail has deleted files from a compromised host after they were exfiltrated.

T1071.001
Web Protocols

BeaverTail has used HTTP GET request to download malicious payloads to include InvisibleFerret and HTTP POST to exfiltrate data to C2 infrastructure.

T1074.001
Local Data Staging

BeaverTail has staged collected data to the system’s temporary directory.

T1082
System Information Discovery

BeaverTail has been known to collect basic system information. BeaverTail has also collected data to include hostname and current timestamp prior to uploading data to the API endpoint `/uploads` on the C2 server.

T1083
File and Directory Discovery

BeaverTail has searched for .ldb and .log files stored in browser extension directories for collection and exfiltration.

T1105
Ingress Tool Transfer

BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret.

T1124
System Time Discovery

BeaverTail has obtained and sent the current timestamp associated with the victim device to C2.

T1195.001
Compromise Software Dependencies and Development Tools

BeaverTail has been hosted on code repositories and disseminated to victims through NPM packages.

T1204.002
Malicious File

BeaverTail has been executed through lures involving malicious JavaScript projects or trojanized remote conferencing software such as MicroTalk or FreeConference. BeaverTail has also been executed through macOS and Windows installers disguised as chat applications.

View all 23 procedure examples

Groups that use it1

Campaigns0

None recorded.

References4

  1. ESET Contagious Interview BeaverTail InvisibleFerret February 2025 Open source
    Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.
  2. Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024 Open source
    eSentire Threat Response Unit (TRU). (2024, November 14). Bored BeaverTail & InvisibleFerret Yacht Club – A Lazarus Lure Pt.2. Retrieved October 17, 2025.
  3. PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023 Open source
    Unit 42. (2023, November 21). Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors. Retrieved October 17, 2025.
  4. Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 Open source
    Seongsu Park. (2024, November 4). From Pyongyang to Your Payroll: The Rise of North Korean Remote Workers in the West. Retrieved October 17, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.