T1001.001 Junk Data |
MalwareBeaverTail |
BeaverTail has added junk data or a dummy character prepended to a string to hamper decoding attempts. |
T1005 Data from Local System |
MalwareBeaverTail |
BeaverTail has exfiltrated data collected from local systems. |
T1027.013 Encrypted/Encoded File |
MalwareBeaverTail |
BeaverTail has obfuscated strings of code with Base64 encoding within the JavaScript version of the malware. BeaverTail has also utilized the open-source tool JavaScript-Obfuscator to obfuscate strings and functions. |
T1036 Masquerading |
MalwareBeaverTail |
BeaverTail has masqueraded as MiroTalk installation packages: “MiroTalk.dmg” for macOS and “MiroTalk.msi” for Windows, and has included login GUIs with MiroTalk themes. |
T1041 Exfiltration Over C2 Channel |
MalwareBeaverTail |
BeaverTail has exfiltrated data collected from victim devices to C2 servers. |
T1059.007 JavaScript |
MalwareBeaverTail |
BeaverTail has executed malicious JavaScript code. BeaverTail has also been compiled with the Qt framework to execute in both Windows and macOS. |
T1070.004 File Deletion |
MalwareBeaverTail |
BeaverTail has deleted files from a compromised host after they were exfiltrated. |
T1071.001 Web Protocols |
MalwareBeaverTail |
BeaverTail has used HTTP GET request to download malicious payloads to include InvisibleFerret and HTTP POST to exfiltrate data to C2 infrastructure. |
T1074.001 Local Data Staging |
MalwareBeaverTail |
BeaverTail has staged collected data to the system’s temporary directory. |
T1082 System Information Discovery |
MalwareBeaverTail |
BeaverTail has been known to collect basic system information. BeaverTail has also collected data to include hostname and current timestamp prior to uploading data to the API endpoint `/uploads` on the C2 server. |
T1083 File and Directory Discovery |
MalwareBeaverTail |
BeaverTail has searched for .ldb and .log files stored in browser extension directories for collection and exfiltration. |
T1105 Ingress Tool Transfer |
MalwareBeaverTail |
BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret. |
T1124 System Time Discovery |
MalwareBeaverTail |
BeaverTail has obtained and sent the current timestamp associated with the victim device to C2. |
T1195.001 Compromise Software Dependencies and Development Tools |
MalwareBeaverTail |
BeaverTail has been hosted on code repositories and disseminated to victims through NPM packages. |
T1204.002 Malicious File |
MalwareBeaverTail |
BeaverTail has been executed through lures involving malicious JavaScript projects or trojanized remote conferencing software such as MicroTalk or FreeConference. BeaverTail has also been executed through macOS and Windows installers disguised as chat applications. |
T1217 Browser Information Discovery |
MalwareBeaverTail |
BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets. |
T1555 Credentials from Password Stores |
MalwareBeaverTail |
BeaverTail has collected keys stored for Solana stored in `.config/solana/id.json` and other login details associated with macOS within `/Library/Keychains/login.keychain` or for Linux within `/.local/share/keyrings`. |
T1555.001 Keychain |
MalwareBeaverTail |
BeaverTail has collected keys associated with macOS within `/Library/Keychains/login.keychain`. |
T1555.003 Credentials from Web Browsers |
MalwareBeaverTail |
BeaverTail has stolen passwords saved in web browsers. BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from `/.mozilla/firefox/` for exfiltration. |
T1560.001 Archive via Utility |
MalwareBeaverTail |
BeaverTail has collected and archived sensitive data in a zip file. |
T1571 Non-Standard Port |
MalwareBeaverTail |
BeaverTail has communicated with C2 IP addresses over ports 1224 or 1244. |
T1654 Log Enumeration |
MalwareBeaverTail |
BeaverTail has identified .ldb and .log files stored in browser extension directories for collection and exfiltration. |
T1657 Financial Theft |
MalwareBeaverTail |
BeaverTail has searched the victim device for browser extensions commonly associated with cryptocurrency wallets. |