Group-IB researchers noticed a Windows version of BeaverTail, which was attributed to Lazarus

2024-08-13 Group-IB

https://archive.is/4xEa8

Thumbnail for Group-IB researchers noticed a Windows version of BeaverTail, which was attributed to Lazarus

Group-IB observed a Windows BeaverTail variant attributed to Lazarus alongside JavaScript BeaverTail distribution through trojanized ReactJS games packaged as NPM-based projects. The Windows sample masqueraded as a conferencing application named FCCCall.exe, consistent with earlier trojanized conferencing-app activity such as MiroTalk. BeaverTail’s described behavior includes stealing cryptocurrency wallet data, expanding targeted browser extensions to Kaikas, Rabby, Argent X, and Exodus Web3, and retrieving the InvisibleFerret next stage. The excerpt provides C2 and hash indicators, supporting detection for Lazarus-linked wallet theft and developer- or crypto-focused infection attempts.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 95.164.17.24 2024-07-15 2026-04-01
IPv4 185.235.241.208 2024-08-13 2025-11-13
HASH 36cac29ff3c503c2123514ea903836d… 2024-08-13 2025-01-20
HASH 0621d37818c35e2557fdd8a729e50ea… 2024-08-13 2024-10-23
HASH d5c0b89e1dfbe9f5e5b2c3f745af895… 2024-08-13 2024-10-09
HASH fd9e8fcc5bda88870b12b47cbb1cc87… 2024-08-13 2024-10-09

Related Actors

Related Reports

« Back