BeaverTail variant distributed via malicious repositories and ClickFix lure
2025-09-17 • Gitlab •
GitLab Threat Intelligence linked infrastructure active since at least May 2025 to North Korean operators distributing BeaverTail and InvisibleFerret variants associated with Contagious Interview and Famous Chollima activity. The campaign used a fake hiring platform at businesshire.top and ClickFix-style camera or microphone troubleshooting lures aimed at cryptocurrency, web3, retail marketing, sales, trader, and investment roles rather than only software developers. The site collected visitor IP, geolocation, and browser cryptocurrency wallet signals before presenting OS-specific commands that fetched payloads from nvidiasdk.fly.dev with numeric user-agent headers as execution guardrails. The infection chains delivered compiled BeaverTail for macOS and Windows, used bundled dependencies and redundancy such as PyInstaller-compiled InvisibleFerret, and showed low static detection despite recognizable network and file-system behavior. The shift toward compiled payloads and non-developer job roles suggests adaptation for victims less likely to have scripting runtimes installed.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://nvidiasdk.fly.dev/nvs | 2025-09-17 | 2026-04-01 |
| DOMAIN | nvidiasdk.fly.dev | 2025-09-17 | 2026-04-01 |
| IPv4 | 172.86.93.139 | 2025-09-17 | 2026-04-01 |
| DOMAIN | api.ipify.org | 2019-12-11 | 2026-03-17 |
| HASH | eba9fdb2f077f9a3e14cf428162b967… | 2025-09-17 | 2026-01-20 |
| HASH | 05ae07783d30b37aa5f0ffff86adde5… | 2025-09-17 | 2025-09-17 |
| HASH | e79b827b3cc29e940736dc20cc9c259… | 2025-09-17 | 2025-09-17 |
| HASH | e224a1db42ae2164d6b2f2a7f1f0e02… | 2025-09-17 | 2025-09-17 |
| HASH | 247fdba5fbfd076d9c530d937406aa0… | 2025-09-17 | 2025-09-17 |
| HASH | 6a16b1ef16e999a0d32a4b9189f6f17… | 2025-09-17 | 2025-09-17 |
| HASH | 9bc46c59e734b2389328a5103739f42… | 2025-09-17 | 2025-09-17 |
| HASH | 4a1588e27a3f322e94e490173fe2bfa… | 2025-09-17 | 2025-09-17 |
| HASH | 25c9fc5c5564a74430b92cb658d43e4… | 2025-09-17 | 2025-09-17 |
| HASH | 65665c3faba4fbfed12488e945306b1… | 2025-09-17 | 2025-09-17 |
| HASH | 17891f7db5a633c0186f3c2c8311a16… | 2025-09-17 | 2025-09-17 |
| [email protected] | 2025-09-17 | 2025-09-17 | |
| [email protected] | 2025-09-17 | 2025-09-17 | |
| URL | https://dmytroviv1.github.io/ | 2025-09-17 | 2025-09-17 |
| URL | https://nvidiasdk.fly..dev/nvs | 2025-09-17 | 2025-09-17 |
| DOMAIN | dmytroviv1.github.io | 2025-09-17 | 2025-09-17 |
| IPv4 | 50.67.15.10 | 2025-09-17 | 2025-09-17 |
| IPv4 | 198.50.130.118 | 2025-09-17 | 2025-09-17 |
| IPv4 | 94.224.115.64 | 2025-09-17 | 2025-09-17 |
| IPv4 | 87.249.132.144 | 2025-09-17 | 2025-09-17 |
| IPv4 | 81.184.178.102 | 2025-09-17 | 2025-09-17 |
| IPv4 | 81.34.167.92 | 2025-09-17 | 2025-09-17 |
| IPv4 | 118.148.107.73 | 2025-09-17 | 2025-09-17 |
| IPv4 | 190.120.252.13 | 2025-09-17 | 2025-09-17 |
| IPv4 | 128.203.96.252 | 2025-09-17 | 2025-09-17 |
| IPv4 | 134.228.221.237 | 2025-09-17 | 2025-09-17 |
| IPv4 | 77.166.75.76 | 2025-09-17 | 2025-09-17 |
| IPv4 | 94.71.186.249 | 2025-09-17 | 2025-09-17 |
| IPv4 | 49.145.111.7 | 2025-09-17 | 2025-09-17 |
| IPv4 | 188.43.33.250 | 2025-04-23 | 2025-09-17 |