Malware.View on attack.mitre.org
BeaverTail is a malware that has both a JavaScript and C++ variant. Active since 2022, BeaverTail is capable of stealing logins from browsers and serves as a downloader for second stage payloads. BeaverTail has previously been leveraged by North Korea-affiliated actors identified as DeceptiveDevelopment or Contagious Interview. BeaverTail has been delivered to victims through code repository sites and has been embedded within malicious attachments.
| Technique | Procedure example |
|---|---|
| T1001.001 Junk Data |
BeaverTail has added junk data or a dummy character prepended to a string to hamper decoding attempts. |
| T1005 Data from Local System |
BeaverTail has exfiltrated data collected from local systems. |
| T1027.013 Encrypted/Encoded File |
BeaverTail has obfuscated strings of code with Base64 encoding within the JavaScript version of the malware. BeaverTail has also utilized the open-source tool JavaScript-Obfuscator to obfuscate strings and functions. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1036 Masquerading |
BeaverTail has masqueraded as MiroTalk installation packages: “MiroTalk.dmg” for macOS and “MiroTalk.msi” for Windows, and has included login GUIs with MiroTalk themes. |
| T1041 Exfiltration Over C2 Channel |
BeaverTail has exfiltrated data collected from victim devices to C2 servers. |
| T1059.007 JavaScript |
BeaverTail has executed malicious JavaScript code. BeaverTail has also been compiled with the Qt framework to execute in both Windows and macOS. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1070.004 File Deletion |
BeaverTail has deleted files from a compromised host after they were exfiltrated. |
| T1071.001 Web Protocols |
BeaverTail has used HTTP GET request to download malicious payloads to include InvisibleFerret and HTTP POST to exfiltrate data to C2 infrastructure. |
| T1074.001 Local Data Staging |
BeaverTail has staged collected data to the system’s temporary directory. |
| T1082 System Information Discovery |
BeaverTail has been known to collect basic system information. BeaverTail has also collected data to include hostname and current timestamp prior to uploading data to the API endpoint `/uploads` on the C2 server. |
| T1083 File and Directory Discovery |
BeaverTail has searched for .ldb and .log files stored in browser extension directories for collection and exfiltration. |
| T1105 Ingress Tool Transfer |
BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1124 System Time Discovery |
BeaverTail has obtained and sent the current timestamp associated with the victim device to C2. |
| T1195.001 Compromise Software Dependencies and Development Tools |
BeaverTail has been hosted on code repositories and disseminated to victims through NPM packages. Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1204.002 Malicious File |
BeaverTail has been executed through lures involving malicious JavaScript projects or trojanized remote conferencing software such as MicroTalk or FreeConference. BeaverTail has also been executed through macOS and Windows installers disguised as chat applications. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.