VORANT. Threat Intelligence Sign in Get the full feed

BeaverTail Malware Gets Native macOS Variant

medium threat

DPRK hackers disguised a native macOS BeaverTail stealer as a cloned MiroTalk video-call app to steal browser/crypto-wallet data and deploy the InvisibleFerret backdoor.

Objective-See analyzed a previously undetected macOS disk image, MiroTalk.dmg, distributed from a fake clone of the legitimate MiroTalk video-conferencing site (mirotalk.net vs. the real meet.no42.org). The unsigned application, internally named "Jami" and built with Qt/QMake, is a native (Mach-O) port of BeaverTail, a JavaScript-based stealer previously documented by Palo Alto Networks Unit42 in DPRK-linked "fake job interview" social-engineering campaigns. The malware harvests macOS Keychain data, browser profile/Local State files from Chrome, Brave and Opera, and targets numerous cryptocurrency wallet browser extensions, exfiltrating the data to a hardcoded C2 at 95.164.17.24:1224.

Beyond credential and wallet theft, the malware fetches additional Python-based payloads from the same C2 via endpoints (/uploads, /pdown, /client/99) matching those Unit42 previously tied to BeaverTail's JavaScript variant. One retrieved payload is a cross-platform Python downloader/executor, and another matches InvisibleFerret, a fully-featured cross-platform backdoor also attributed to the same DPRK operation. The C2 server has been previously flagged as North Korean infrastructure.

The campaign relies on social engineering — luring victims, likely job seekers or those solicited for fake hiring/interview meetings, into running the malicious "MiroTalk" app — rather than any novel exploit. Objective-See notes its free tools BlockBlock (Notarization Mode) and LuLu can respectively block execution of the unnotarized binary and alert on its outbound C2 connection, providing detection even without prior signature knowledge.

Mentioned in this report

Threat actors DPRK-nexus actors
Malware BeaverTailInvisibleFerret
Campaigns Contagious Interview

Source reporting: https://objective-see.org/blog/blog_0x7A.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free