North Korean Hackers Update BeaverTail Malware to Target MacOS Users
ID: 875ae373-a464-542f-8a19-1ad1f9cbf1d7
STIX ID: report--875ae373-a464-542f-8a19-1ad1f9cbf1d7
Feed Name: The Hacker News
Cybersecurity researchers have identified a DPRK-linked campaign delivering an updated BeaverTail JavaScript stealer via a malicious MiroTalk installer (macOS DMG and Windows MSI) and weaponized npm packages; the malware exfiltrates browser data, crypto wallets and iCloud Keychain, can fetch additional payloads (InvisibleFerret Python backdoor and AnyDesk for persistence), and mirrors legitimate software to socially engineer job-seeking developers into installing the trojanized applications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
