logo

BeaverTail and Tropidoor Malware Distributed via Recruitment Emails

ID: bf9cc65a-243c-5513-8dcd-c2999c512770

STIX ID: report--bf9cc65a-243c-5513-8dcd-c2999c512770

Feed Name: ASEC

Threat Score
85/100

Date Published: 2025-04-01

Date Updated: 2026-04-26

Author: ATCP

...
...

A campaign impersonating developer recruitment distributed a BitBucket project containing BeaverTail (tailwind.config.js) infostealer and a downloader (car.dll/img_layer_generate.dll); the downloader executed, fetched additional payloads (p.zi, p2.zip), and deployed a backdoor (Tropidoor) with RSA/Session-key C2 communications and a wide command set including remote command execution. The report links these artifacts and behaviors to North Korean-associated malware families (BeaverTail, similarities to Lazarus/LightlessCan), provides MD5s, IPs and URLs as IOCs, and recommends caution with unsolicited repositories and keeping AV signatures updated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.