logo

Beware! Malicious Recruitment Emails Deliver BeaverTail and Tropidoor Malware Payloads

ID: b24fb940-73b4-5685-abb5-bed82399c633

STIX ID: report--b24fb940-73b4-5685-abb5-bed82399c633

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2025-04-04

Date Updated: 2026-04-13

Author: Mandvi

...
...

### Executive Summary A phishing campaign targeting developers used fake job postings and BitBucket-hosted files to deliver obfuscated JavaScript infostealer 'BeaverTail' and a downloader 'car.dll' that installs the in-memory backdoor 'Tropidoor'; the report links these tools and tactics to the Lazarus APT and includes file hashes, IPs, and URLs as IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.