Beware! Weaponized Job Recruitment Emails Spreading BeaverTail and Tropidoor Malware
ID: 44a00bc7-d913-5e05-ada5-d1765d3088ba
STIX ID: report--44a00bc7-d913-5e05-ada5-d1765d3088ba
Feed Name: GBHackers
Threat Score
AhnLab ASEC disclosed a campaign where attackers impersonated Dev.to and used a BitBucket-hosted project to deliver BeaverTail (a JavaScript infostealer/downloader) and Tropidoor (a memory-resident backdoor). The report details malware behaviors (credential and crypto wallet theft, downloader activity, C2 communications, and command execution), provides file hashes, malicious URLs and IPs as IoCs, and attributes the activity to North Korean-linked actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
