# BeaverTail Malware Gets Native macOS Variant

Published: 2024-06-15 · Severity: medium
Canonical: https://vorant.io/reports/4ca111bf-3582-529f-9b0a-030c0d5c7d39/beavertail-malware-gets-native-macos-variant

> DPRK hackers disguised a native macOS BeaverTail stealer as a cloned MiroTalk video-call app to steal browser/crypto-wallet data and deploy the InvisibleFerret backdoor.

Objective-See analyzed a previously undetected macOS disk image, MiroTalk.dmg, distributed from a fake clone of the legitimate MiroTalk video-conferencing site (mirotalk.net vs. the real meet.no42.org). The unsigned application, internally named "Jami" and built with Qt/QMake, is a native (Mach-O) port of BeaverTail, a JavaScript-based stealer previously documented by Palo Alto Networks Unit42 in DPRK-linked "fake job interview" social-engineering campaigns. The malware harvests macOS Keychain data, browser profile/Local State files from Chrome, Brave and Opera, and targets numerous cryptocurrency wallet browser extensions, exfiltrating the data to a hardcoded C2 at 95.164.17.24:1224.

Beyond credential and wallet theft, the malware fetches additional Python-based payloads from the same C2 via endpoints (/uploads, /pdown, /client/99) matching those Unit42 previously tied to BeaverTail's JavaScript variant. One retrieved payload is a cross-platform Python downloader/executor, and another matches InvisibleFerret, a fully-featured cross-platform backdoor also attributed to the same DPRK operation. The C2 server has been previously flagged as North Korean infrastructure.

The campaign relies on social engineering — luring victims, likely job seekers or those solicited for fake hiring/interview meetings, into running the malicious "MiroTalk" app — rather than any novel exploit. Objective-See notes its free tools BlockBlock (Notarization Mode) and LuLu can respectively block execution of the unnotarized binary and alert on its outbound C2 connection, providing detection even without prior signature knowledge.

## Mentioned in this report

- Threat actors: DPRK-nexus actors
- Malware: BeaverTail, InvisibleFerret
- Campaigns: Contagious Interview

Source reporting: https://objective-see.org/blog/blog_0x7A.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4ca111bf-3582-529f-9b0a-030c0d5c7d39/beavertail-malware-gets-native-macos-variant.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
