Group-IB researchers noticed a Windows version of BeaverTail, which was attributed to Lazarus
2024-08-13 • Group-IB •
Group-IB observed a Windows BeaverTail variant attributed to Lazarus alongside JavaScript BeaverTail distribution through trojanized ReactJS games packaged as NPM-based projects. The Windows sample masqueraded as a conferencing application named FCCCall.exe, consistent with earlier trojanized conferencing-app activity such as MiroTalk. BeaverTail’s described behavior includes stealing cryptocurrency wallet data, expanding targeted browser extensions to Kaikas, Rabby, Argent X, and Exodus Web3, and retrieving the InvisibleFerret next stage. The excerpt provides C2 and hash indicators, supporting detection for Lazarus-linked wallet theft and developer- or crypto-focused infection attempts.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 95.164.17.24 | 2024-07-15 | 2026-04-01 |
| IPv4 | 185.235.241.208 | 2024-08-13 | 2025-11-13 |
| HASH | 8ebca0b7ef7dbfc14da3ee39f478e880 | 2024-08-13 | 2025-01-20 |
| HASH | ed60b3913e6694f4a0ed2fe25551bd1f | 2024-08-13 | 2024-08-13 |
| HASH | dc77044fe8d35882015eaa99ca31f826 | 2024-08-13 | 2024-08-13 |
| HASH | b9693b6541a22d01b100b867375279e6 | 2024-08-13 | 2024-08-13 |