logo

Beware! Weaponized Job Recruitment Emails Spreading BeaverTail and Tropidoor Malware

ID: 44a00bc7-d913-5e05-ada5-d1765d3088ba

STIX ID: report--44a00bc7-d913-5e05-ada5-d1765d3088ba

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2025-04-04

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

AhnLab ASEC disclosed a campaign where attackers impersonated Dev.to and used a BitBucket-hosted project to deliver BeaverTail (a JavaScript infostealer/downloader) and Tropidoor (a memory-resident backdoor). The report details malware behaviors (credential and crypto wallet theft, downloader activity, C2 communications, and command execution), provides file hashes, malicious URLs and IPs as IoCs, and attributes the activity to North Korean-linked actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.