BeaverTail variant distributed via malicious repositories and ClickFix lure

2025-09-17 Gitlab

https://gitlab-com.gitlab.io/gl-security/security-tech-notes/threat-intelligence-tech-notes/north-korean-malware-sept-2025/

Thumbnail for BeaverTail variant distributed via malicious repositories and ClickFix lure

GitLab Threat Intelligence linked infrastructure active since at least May 2025 to North Korean operators distributing BeaverTail and InvisibleFerret variants associated with Contagious Interview and Famous Chollima activity. The campaign used a fake hiring platform at businesshire.top and ClickFix-style camera or microphone troubleshooting lures aimed at cryptocurrency, web3, retail marketing, sales, trader, and investment roles rather than only software developers. The site collected visitor IP, geolocation, and browser cryptocurrency wallet signals before presenting OS-specific commands that fetched payloads from nvidiasdk.fly.dev with numeric user-agent headers as execution guardrails. The infection chains delivered compiled BeaverTail for macOS and Windows, used bundled dependencies and redundancy such as PyInstaller-compiled InvisibleFerret, and showed low static detection despite recognizable network and file-system behavior. The shift toward compiled payloads and non-developer job roles suggests adaptation for victims less likely to have scripting runtimes installed.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://nvidiasdk.fly.dev/nvs 2025-09-17 2026-04-01
DOMAIN nvidiasdk.fly.dev 2025-09-17 2026-04-01
IPv4 172.86.93.139 2025-09-17 2026-04-01
DOMAIN api.ipify.org 2019-12-11 2026-03-17
HASH eba9fdb2f077f9a3e14cf428162b967… 2025-09-17 2026-01-20
HASH 05ae07783d30b37aa5f0ffff86adde5… 2025-09-17 2025-09-17
HASH e79b827b3cc29e940736dc20cc9c259… 2025-09-17 2025-09-17
HASH e224a1db42ae2164d6b2f2a7f1f0e02… 2025-09-17 2025-09-17
HASH 247fdba5fbfd076d9c530d937406aa0… 2025-09-17 2025-09-17
HASH 6a16b1ef16e999a0d32a4b9189f6f17… 2025-09-17 2025-09-17
HASH 9bc46c59e734b2389328a5103739f42… 2025-09-17 2025-09-17
HASH 4a1588e27a3f322e94e490173fe2bfa… 2025-09-17 2025-09-17
HASH 25c9fc5c5564a74430b92cb658d43e4… 2025-09-17 2025-09-17
HASH 65665c3faba4fbfed12488e945306b1… 2025-09-17 2025-09-17
HASH 17891f7db5a633c0186f3c2c8311a16… 2025-09-17 2025-09-17
EMAIL [email protected] 2025-09-17 2025-09-17
EMAIL [email protected] 2025-09-17 2025-09-17
URL https://dmytroviv1.github.io/ 2025-09-17 2025-09-17
URL https://nvidiasdk.fly..dev/nvs 2025-09-17 2025-09-17
DOMAIN dmytroviv1.github.io 2025-09-17 2025-09-17
IPv4 50.67.15.10 2025-09-17 2025-09-17
IPv4 198.50.130.118 2025-09-17 2025-09-17
IPv4 94.224.115.64 2025-09-17 2025-09-17
IPv4 87.249.132.144 2025-09-17 2025-09-17
IPv4 81.184.178.102 2025-09-17 2025-09-17
IPv4 81.34.167.92 2025-09-17 2025-09-17
IPv4 118.148.107.73 2025-09-17 2025-09-17
IPv4 190.120.252.13 2025-09-17 2025-09-17
IPv4 128.203.96.252 2025-09-17 2025-09-17
IPv4 134.228.221.237 2025-09-17 2025-09-17
IPv4 77.166.75.76 2025-09-17 2025-09-17
IPv4 94.71.186.249 2025-09-17 2025-09-17
IPv4 49.145.111.7 2025-09-17 2025-09-17
IPv4 188.43.33.250 2025-04-23 2025-09-17

Related Reports

« Back