BeaverTail and Tropidoor Malware Distributed via Recruitment Emails
ID: bf9cc65a-243c-5513-8dcd-c2999c512770
STIX ID: report--bf9cc65a-243c-5513-8dcd-c2999c512770
Feed Name: ASEC
A campaign impersonating developer recruitment distributed a BitBucket project containing BeaverTail (tailwind.config.js) infostealer and a downloader (car.dll/img_layer_generate.dll); the downloader executed, fetched additional payloads (p.zi, p2.zip), and deployed a backdoor (Tropidoor) with RSA/Session-key C2 communications and a wide command set including remote command execution. The report links these artifacts and behaviors to North Korean-associated malware families (BeaverTail, similarities to Lazarus/LightlessCan), provides MD5s, IPs and URLs as IOCs, and recommends caution with unsolicited repositories and keeping AV signatures updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
