채용 메일을 위장한 피싱 공격 정황 사례 분석 (BeaverTail, Tropidoor)

2025-04-02 Ahnlab Case Analysis of Phishing Activity Disguised as Recruitment Email (BeaverTail, Tropidoor)

https://asec.ahnlab.com/ko/87227/

Thumbnail for 채용 메일을 위장한 피싱 공격 정황 사례 분석 (BeaverTail, Tropidoor)

AhnLab analyzes a recruitment-themed phishing case distributing BeaverTail and Tropidoor-related malware through project files shared as a Bitbucket link. The archive describes a JavaScript BeaverTail component, downloader DLLs such as car.dll, and behavior consistent with credential and cryptocurrency wallet theft, additional payload download, and execution patterns previously associated with North Korean operators. The report also notes overlap with Lazarus LightlessCan-style command implementation and includes C2 and hash indicators for hunting related developer-targeted intrusions.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 45.8.146.93 2025-04-02 2025-09-25
IPv4 86.104.72.247 2025-04-02 2025-09-25
IPv4 103.35.190.170 2025-04-02 2025-09-25
HASH 420af4aaac771db407ca02ca51912a2… 2025-04-02 2025-04-02
HASH e967097a02185995ae58cded08f57e8… 2025-04-02 2025-04-02
HASH f855e04d69dce32e062e4a08b073e68… 2025-04-02 2025-04-02
HASH 1fd921159de8ccf3c33c7ad3d52a418… 2025-04-02 2025-04-02

Related Reports

« Back