BeaverTail & InvisibleFerret
2025-02-07 • SICERT •
Attackers posed as job seekers or collaboration partners, typically approaching victims through LinkedIn and sending a seemingly legitimate project that executed malicious code when run. The activity targeted Web3 companies and individuals working with smart contracts, cryptocurrency, and blockchain, using an NPM package with obfuscated JavaScript hidden in a local route module. The first-stage script sent host identifiers and metadata to http://23.106.253.221:1244/keys, then created a .vscode directory, downloaded test.js and package.json from the same server, installed dependencies, and executed the next payload. The downloaded BeaverTail Node.js module stole browser and cryptocurrency-wallet data from extensions such as MetaMask, TronLink, BNB Chain Wallet, Coinbase Wallet, Phantom, and Coin98, uploading data to http://23.106.253.221:1244/uploads. The source does not make its own attribution, but notes that other security research has linked similar tradecraft and malware to North Korean state-sponsored activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 23.106.253.221 | 2025-02-07 | 2025-11-13 |
| HASH | 6a104f07ab6c5711b6bc8bf6ff956ab… | 2024-10-23 | 2025-07-26 |
| IPv4 | 173.211.106.101 | 2024-04-25 | 2025-07-26 |
| HASH | 354e7014103783c2096b9f29e4eed11… | 2025-02-07 | 2025-02-07 |
| HASH | 6b331ab212a839ad1b1b673ca74a3c5… | 2025-02-07 | 2025-02-07 |
| HASH | 95e3cbaac2749928598928c3b8ca803… | 2025-02-07 | 2025-02-07 |
| HASH | f46b47e859f321b6676289f3637538b… | 2025-02-07 | 2025-02-07 |
| HASH | 335ad22f143ff050bb405cd48d0011a… | 2025-02-07 | 2025-02-07 |
| HASH | 4f632429fedb39fa2addaeff3ba9006… | 2025-02-07 | 2025-02-07 |