Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware
ID: df8c4de3-2507-5336-9183-b41fc481bce5
STIX ID: report--df8c4de3-2507-5336-9183-b41fc481bce5
Feed Name: Palo Alto Networks Unit 42
Threat Score
Unit 42 reports on the CL-STA-0240 campaign attributed to DPRK-linked actors who impersonate recruiters to deliver a cross-platform Qt-based BeaverTail downloader that installs the InvisibleFerret Python backdoor; the malware steals browser credentials and cryptocurrency wallet data, enables remote control and data exfiltration, and the report provides technical analysis, IoCs (hashes and C2 IPs), and recommended protections including Cortex XDR detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
