BeaverTail & InvisibleFerret

2025-02-07 SICERT

https://www.cert.si/tz016/

Thumbnail for BeaverTail & InvisibleFerret

Attackers posed as job seekers or collaboration partners, typically approaching victims through LinkedIn and sending a seemingly legitimate project that executed malicious code when run. The activity targeted Web3 companies and individuals working with smart contracts, cryptocurrency, and blockchain, using an NPM package with obfuscated JavaScript hidden in a local route module. The first-stage script sent host identifiers and metadata to http://23.106.253.221:1244/keys, then created a .vscode directory, downloaded test.js and package.json from the same server, installed dependencies, and executed the next payload. The downloaded BeaverTail Node.js module stole browser and cryptocurrency-wallet data from extensions such as MetaMask, TronLink, BNB Chain Wallet, Coinbase Wallet, Phantom, and Coin98, uploading data to http://23.106.253.221:1244/uploads. The source does not make its own attribution, but notes that other security research has linked similar tradecraft and malware to North Korean state-sponsored activity.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 23.106.253.221 2025-02-07 2025-11-13
HASH 6a104f07ab6c5711b6bc8bf6ff956ab… 2024-10-23 2025-07-26
IPv4 173.211.106.101 2024-04-25 2025-07-26
HASH 354e7014103783c2096b9f29e4eed11… 2025-02-07 2025-02-07
HASH 6b331ab212a839ad1b1b673ca74a3c5… 2025-02-07 2025-02-07
HASH 95e3cbaac2749928598928c3b8ca803… 2025-02-07 2025-02-07
HASH f46b47e859f321b6676289f3637538b… 2025-02-07 2025-02-07
HASH 335ad22f143ff050bb405cd48d0011a… 2025-02-07 2025-02-07
HASH 4f632429fedb39fa2addaeff3ba9006… 2025-02-07 2025-02-07

Related Reports

2025-02-20 • 60% Match
#BeaverTail #InvisibleFerret #DeceptiveDevelopment #T1027.013 #T1082 #T1119 #T1059.003 #T1140 #T1005 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1115 #T1083 #T1056.001 #T1059.006 #T1059.007 #T1204.002 #T1566.003 #T1555.003 #T1124 #T1583.003 #T1552.001 #T1585.001 #T1219 #T1133 #T1571 #T1564.001 #T1016 #T1074.001 #T1657 #T1071.002 #T1021.001 #T1614 #T1555.001 #T1217 #T1095 #T1025 #T1010 #T1560.002 #T1030 #T1567.004 #T1564.003
Shares tags: BeaverTail, InvisibleFerret • Published within a month
« Back