Group-IB researchers noticed a Windows version of BeaverTail, which was attributed to Lazarus

2024-08-13 Group-IB

https://archive.is/4xEa8

Thumbnail for Group-IB researchers noticed a Windows version of BeaverTail, which was attributed to Lazarus

Group-IB observed a Windows BeaverTail variant attributed to Lazarus alongside JavaScript BeaverTail distribution through trojanized ReactJS games packaged as NPM-based projects. The Windows sample masqueraded as a conferencing application named FCCCall.exe, consistent with earlier trojanized conferencing-app activity such as MiroTalk. BeaverTail’s described behavior includes stealing cryptocurrency wallet data, expanding targeted browser extensions to Kaikas, Rabby, Argent X, and Exodus Web3, and retrieving the InvisibleFerret next stage. The excerpt provides C2 and hash indicators, supporting detection for Lazarus-linked wallet theft and developer- or crypto-focused infection attempts.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 95.164.17.24 2024-07-15 2026-04-01
IPv4 185.235.241.208 2024-08-13 2025-11-13
HASH 8ebca0b7ef7dbfc14da3ee39f478e880 2024-08-13 2025-01-20
HASH ed60b3913e6694f4a0ed2fe25551bd1f 2024-08-13 2024-08-13
HASH dc77044fe8d35882015eaa99ca31f826 2024-08-13 2024-08-13
HASH b9693b6541a22d01b100b867375279e6 2024-08-13 2024-08-13

Related Actors

Related Reports

« Back