North Korean Malware Analysis: Unveiling a Stealthy Cyberattack
Security researchers uncovered a cyberattack campaign attributed to North Korean APTs. The campaign used malware disguised as a job application challenge (BeaverTail) to lure victims. BeaverTail, surprisingly un-obfuscated, steals cryptocurrency wallet information from browsers and downloads a second-stage malware, InvisibleFerret. InvisibleFerret further exfiltrates browser data, clipboard information, and acts as a Remote Access Trojan (RAT). Analysis of BeaverTail and InvisibleFerret revealed a simplistic code structure yet effective capabilities to steal information from various browsers and operating systems. This case highlights the persistence and stealth of North Korean cyber threats.