Malware.View on attack.mitre.org
HexEval Loader is a hex-encoded loader that collects host data, decodes follow-on scripts and acts as a downloader for the BeaverTail malware. HexEval Loader was first reported in April 2025. HexEval Loader has previously been leveraged by North Korea-affiliated threat actors identified as Contagious Interview. HexEval Loader has been delivered to victims through code repository sites utilizing typosquatting naming conventions of various npm packages.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
HexEval Loader has leveraged server-side client configurations to identify the public IP of the victim host. |
| T1027.013 Encrypted/Encoded File |
HexEval Loader has encoded module names and C2 URLs as hexadecimal strings in attempts to evade analysis. |
| T1033 System Owner/User Discovery |
HexEval Loader has collected the username from the victim host. |
| T1036.005 Match Legitimate Resource Name or Location |
HexEval Loader has masqueraded and typosquatted as legitimate code repository packages and projects. |
| T1041 Exfiltration Over C2 Channel |
HexEval Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers. |
| T1056.001 Keylogging |
HexEval Loader has utilized a cross-platform keylogger that has the capability to capture keystrokes on Windows, macOS and Linux systems. |
| T1059.007 JavaScript |
HexEval Loader has executed malicious JavaScript code. |
| T1071.001 Web Protocols |
HexEval Loader has used HTTP and HTTPS POST requests to communicate with C2. |
| T1082 System Information Discovery |
HexEval Loader has identified the OS and MAC address of victim device through host fingerprinting scripting. |
| T1105 Ingress Tool Transfer |
HexEval Loader has been used to download a malicious payload to include BeaverTail. |
| T1140 Deobfuscate/Decode Files or Information |
HexEval Loader has decoded its payload prior to execution. |
| T1614 System Location Discovery |
HexEval Loader has a function where the C2 endpoint can identify the geographical location of a victim host based on request headers, execution environment and runtime conditions. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.