#Tsunami
Malware/Tool
Tsunami is an actively developed, modular malware framework used in North Korea-linked cryptocurrency theft against software developers. It targets Windows as part of the Contagious Interview and DeceptiveDevelopment activity, which uses fake recruiters, staged job interviews, ClickFix, and trojanized codebases for access. One observed chain loaded BeaverTail from a third-party domain through a private GitHub repository, then deployed InvisibleFerret and a Python launcher. The framework installs an injector in the Startup folder, places its installer as Runtime Broker.exe, adds a Microsoft Defender exclusion, and creates a scheduled task. Its modules include credential stealers and cryptocurrency miners, while command-and-control relies on Pastebin accounts and Tor onion services.
-
3
Tagged Reports
-
3
Unique Authors
-
215
Active Days