logo

Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware

ID: df8c4de3-2507-5336-9183-b41fc481bce5

STIX ID: report--df8c4de3-2507-5336-9183-b41fc481bce5

Feed Name: Palo Alto Networks Unit 42

Threat Score
85/100

Date Published: 2024-10-09

Date Updated: 2026-04-28

Author: Unit 42

...
...

Unit 42 reports on the CL-STA-0240 campaign attributed to DPRK-linked actors who impersonate recruiters to deliver a cross-platform Qt-based BeaverTail downloader that installs the InvisibleFerret Python backdoor; the malware steals browser credentials and cryptocurrency wallet data, enables remote control and data exfiltration, and the report provides technical analysis, IoCs (hashes and C2 IPs), and recommended protections including Cortex XDR detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.