채용 메일을 위장한 피싱 공격 정황 사례 분석 (BeaverTail, Tropidoor)
2025-04-02 • Ahnlab • Case Analysis of Phishing Activity Disguised as Recruitment Email (BeaverTail, Tropidoor) •
AhnLab analyzes a recruitment-themed phishing case distributing BeaverTail and Tropidoor-related malware through project files shared as a Bitbucket link. The archive describes a JavaScript BeaverTail component, downloader DLLs such as car.dll, and behavior consistent with credential and cryptocurrency wallet theft, additional payload download, and execution patterns previously associated with North Korean operators. The report also notes overlap with Lazarus LightlessCan-style command implementation and includes C2 and hash indicators for hunting related developer-targeted intrusions.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 45.8.146.93 | 2025-04-02 | 2025-09-25 |
| IPv4 | 86.104.72.247 | 2025-04-02 | 2025-09-25 |
| IPv4 | 103.35.190.170 | 2025-04-02 | 2025-09-25 |
| HASH | b29ddcc9affdd56a520f23a61b670134 | 2025-04-02 | 2025-04-02 |
| HASH | 94ef379e332f3a120ab16154a7ee7a00 | 2025-04-02 | 2025-04-02 |
| HASH | 3aed5502118eb9b8c9f8a779d4b09e11 | 2025-04-02 | 2025-04-02 |
| HASH | 84d25292717671610c936bca7f0626f5 | 2025-04-02 | 2025-04-02 |