T1005 Data from Local System |
MalwareBeaverTail |
BeaverTail has exfiltrated data collected from local systems. |
T1027.013 Encrypted/Encoded File |
MalwareBeaverTail |
BeaverTail has obfuscated strings of code with Base64 encoding within the JavaScript version of the malware. BeaverTail has also utilized the open-source tool JavaScript-Obfuscator to obfuscate strings and functions. |
T1036 Masquerading |
MalwareBeaverTail |
BeaverTail has masqueraded as MiroTalk installation packages: “MiroTalk.dmg” for macOS and “MiroTalk.msi” for Windows, and has included login GUIs with MiroTalk themes. |
T1036 Masquerading |
GroupContagious Interview |
Contagious Interview has delivered BeaverTail malware masquerading as legitimate software or applications. Contagious Interview has also delivered malicious payloads masquerading as legitimate software drivers. |
T1041 Exfiltration Over C2 Channel |
MalwareBeaverTail |
BeaverTail has exfiltrated data collected from victim devices to C2 servers. |
T1041 Exfiltration Over C2 Channel |
GroupContagious Interview |
Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers. |
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupContagious Interview |
Contagious Interview has exfiltrated victim information using FTP. |
T1059.007 JavaScript |
MalwareBeaverTail |
BeaverTail has executed malicious JavaScript code. BeaverTail has also been compiled with the Qt framework to execute in both Windows and macOS. |
T1083 File and Directory Discovery |
MalwareInvisibleFerret |
InvisibleFerret has identified specific directories and files for exfiltration using the `ssh_upload` command which contains subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr`, `sfind`. InvisibleFerret also has the capability to scan and upload files of interest from multiple OS systems through the use of scripts that check file names, file extensions, and avoids certain path names. InvisibleFerret has utilized the `findstr` on Windows or the macOS `find` commands to search for files of interest. |
T1105 Ingress Tool Transfer |
MalwareBeaverTail |
BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret. |
T1195.001 Compromise Software Dependencies and Development Tools |
MalwareBeaverTail |
BeaverTail has been hosted on code repositories and disseminated to victims through NPM packages. |
T1204.002 Malicious File |
MalwareBeaverTail |
BeaverTail has been executed through lures involving malicious JavaScript projects or trojanized remote conferencing software such as MicroTalk or FreeConference. BeaverTail has also been executed through macOS and Windows installers disguised as chat applications. |
T1217 Browser Information Discovery |
MalwareBeaverTail |
BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets. |
T1219.002 Remote Desktop Software |
GroupContagious Interview |
Contagious Interview has downloaded remote management and monitoring software such as “AnyDesk” for post compromise activities. |
T1555.003 Credentials from Web Browsers |
MalwareBeaverTail |
BeaverTail has stolen passwords saved in web browsers. BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from `/.mozilla/firefox/` for exfiltration. |
T1571 Non-Standard Port |
MalwareBeaverTail |
BeaverTail has communicated with C2 IP addresses over ports 1224 or 1244. |
T1583.001 Domains |
GroupContagious Interview |
Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2. |
T1585.001 Social Media Accounts |
GroupContagious Interview |
Contagious Interview has created fake social media accounts such as LinkedIn and Telegram accounts for their targeting efforts. |
T1585.002 Email Accounts |
GroupContagious Interview |
Contagious Interview has created fake email accounts to correspond with social media accounts, fake LinkedIn personas, code repository accounts, and job announcements on development job board services. Contagious Interview has also utilized fake email accounts with Threat Intelligence vendor services. |
T1587.001 Malware |
GroupContagious Interview |
Contagious Interview has developed malware that utilizes Qt cross-platform framework to include BeaverTail. |
T1588.002 Tool |
GroupContagious Interview |
Contagious Interview has used remote management and monitoring software such as “AnyDesk”. |
T1589 Gather Victim Identity Information |
GroupContagious Interview |
Contagious Interview has researched specific professional groups such as software developers for targeting. Contagious Interview has also researched individuals who work in roles related to cryptocurrency and blockchain technologies. |
T1593.001 Social Media |
GroupContagious Interview |
Contagious Interview had identified and solicited victims through social media such as LinkedIn, X, and Telegram. |
T1657 Financial Theft |
GroupContagious Interview |
Contagious Interview has stolen cryptocurrency wallet credentials and credit card information utilizing BeaverTail and InvisibleFerret malware. |
T1657 Financial Theft |
MalwareBeaverTail |
BeaverTail has searched the victim device for browser extensions commonly associated with cryptocurrency wallets. |
T1683.002 Audio-Visual Content |
GroupContagious Interview |
Contagious Interview has used AI to clone video-conferencing applications to distribute their BeaverTail malware. They have also used AI to create deepfake videos. |
T1684.001 Impersonation |
GroupContagious Interview |
Contagious Interview had impersonated HR hiring personnel through social media, job board notifications, and conducted interviews with victims in order to entice them to download malware disguised as legitimate applications or malicious scripts from code repositories. |