logo

New BeaverTail Malware Variant Linked to Lazarus Group

ID: 9e114b41-4a8b-52d2-83a4-2d76dac553d8

STIX ID: report--9e114b41-4a8b-52d2-83a4-2d76dac553d8

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2025-12-18

Date Updated: 2026-04-22

...
...

Darktrace reports a hyper-obfuscated BeaverTail JavaScript malware variant linked to DPRK/Lazarus actors that functions as an infostealer and loader targeting cryptocurrency traders, developers and retail employees. Delivered via trojanized npm packages, fake job-assessment platforms and social-engineering lures, the cross-platform framework collects host and credential data, fetches additional payloads, and has been observed merged with OtterCookie to enhance wallet targeting, persistence and surveillance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.