Wednesday, January 22, 2025
Homecyber securityBeaverTail Malware Attacking Windows Users Via Weaponized Games

BeaverTail Malware Attacking Windows Users Via Weaponized Games

Published on

SIEM as a Service

Follow Us on Google News

Researchers uncovered a new malware campaign dubbed BeaverTail, a North Korean cyber espionage malware family primarily focusing on job seekers.

Initially identified as a JavaScript-based info stealer, it has since morphed into a native macOS version that pretends to be legitimate software like the MiroTalk video call service.

This malware is designed to steal confidential information from contaminated computers, including browser data and cryptocurrency wallets.

Cybersecurity researchers at Group-IB Threat Intelligence recently discovered that BeaverTail malware has been attacking Windows users via weaponized games.

Technical Analysis

Two new developments in the BeaverTail malware family were discovered by Group-IB’s cybersecurity specialists.

Firstly, they detected a new Windows version of BeaverTail, expanding the malware’s reach beyond its previous platforms. Secondly, and perhaps more alarmingly, they uncovered an evolved JavaScript variant of BeaverTail. 

This version circulates through innocent titles. It is built on ReactJS, a widely used JavaScript library for popular games.

These malicious applications are hidden inside NPM (Node Package Manager) packages and can easily be included in multiple development projects.

Through this sophisticated exploit, the Lazarus group has shown to be adaptive enough in their attempt to attack different operating systems and dev environments.

BeaverTail malware for Windows has been seen to disguise itself as a genuine conferencing app FCCCall.exe.

This is similar to an earlier Lazarus operation where the group trojanized the MiroTalk application.

Moreover, this most recent campaign was likely conducted between late July and early August, showing the group’s susceptibility to leveraging communication software in targeting host devices.

Two primary objectives remain the same for all BeaverTail versions, fetching cryptocurrency wallet information and downloading and executing the next-step payload, InvisibleFerret.

However, the malware’s developers broadened its scope as shown by the increasing number of browser extensions it targets.

BeaverTail now compromises a broader range of browser extensions including those previously mentioned such as kaikas, rabby, argent X, and Exodus web3 which suggests that its operators intend to capture a greater volume of victims’ cryptocurrency assets.

IoCs

  • 185.235.241[.]208:1224
  • 95.164.17[.]24:1224
  • dc77044fe8d35882015eaa99ca31f826
  • b9693b6541a22d01b100b867375279e6
  • 8ebca0b7ef7dbfc14da3ee39f478e880
  • ed60b3913e6694f4a0ed2fe25551bd1f

Are you from SOC and DFIR Teams? Analyse Malware Incidents & get live Access with ANY.RUN -> Get 14 Days Free Acces

Kaaviya
Kaaviya
Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Latest articles

SQL Injection Vulnerability in Microsoft’s DevBlogs Lets Hackers Injecting Malicious SQL

In a recent discovery, a security researcher uncovered a critical SQL injection vulnerability on...

Three New ICS Advisories Released by CISA Detailing Vulnerabilities & Mitigations

The Cybersecurity and Infrastructure Security Agency (CISA) announced three new Industrial Control Systems (ICS)...

Security Researchers Discover Critical RCE Vulnerability, Earned $40,000 Bounty

Cybersecurity researchers Abdullah Nawaf and Orwa Atyat, successfully escalated a limited path traversal vulnerability...

IBM i Access Client Solutions Might Be Leaking Your Passwords

A potential security flaw in IBM i Access Client Solutions (ACS) has raised serious...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Beware! Fake SBI Reward APK Attacking Users to Deliver Android Malware

A recent phishing campaign has targeted customers of SBI Bank through a deceptive message...

Gootloader Malware Employs Blackhat SEO Techniques To Attack Victims

The Gootloader malware family employs sophisticated social engineering tactics to infiltrate computers.By leveraging...

Microsoft Rolls Out New Administrator Protection Feature Under Windows Security

Microsoft has announced the release of Windows 11 Insider Preview Build 27774 to the...