Security Market Segment LS
Friday, 19 December 2025 12:58

Darktrace researchers discover devilishly deadly new BeaverTail malware variant linked to Lazarus Group Featured

By

Darktrace threat researchers have identified and analyzed a new variant of BeaverTail, a malware family associated with North Korea’s Lazarus Group activity. BeaverTail is a JavaScript-based information stealer and malware loader that has been active since 2022.

Founded in 2012, Darktrace bills itself as a global leader in AI for cybersecurity that keeps organisations ahead of the changing threat landscape every day, with proprietary AI that learns from the unique patterns of life for each customer in real-time to proactively deal with unknown threats.

This enables it to secure businesses across the entire digital estate – from network to cloud to email, and with over 200 patents filed, protecting nearly 10,000 customers across all major industries globally, the company is clearly shining a very bright light so it can proactively trace everything that happens in, on and around the dark side of the web.

That snippet of poetic allegory aside, and the news from earlier this month that Darktrace is a "Leader" in TWO of Gartner's Magic Quadrants, being for ESP (Email Security Platform) and for NDR (Network Detection and Response), and we have a company that clearly knows how to navigate the dark arts with skill, aided with aplomb by AI, and lots of very smart people.

So, what of the Beaver's tale resurrected by the dark forces at Lazarus?

Darktrace traces this newly identified strain identified and says it represents a significant technical evolution of the variant, with new characteristics including:

  • Deep obfuscation: BeaverTail has previously employed obfuscation, but this sample contains more than 128 layers dedicated entirely to concealment, a depth not seen in earlier versions.
  • Signature evasion: Its code has evolved to bypass traditional signature‑based defenses, underscoring Lazarus’s continued refinement of malware to slip past trusted security tools. 

Over time, BeaverTail has transformed and evolved from a lightweight stealer into what is now a deeply disturbing dollop of digital destruction: a multi‑stage intrusion framework designed for persistence, stealth, and financial/data theft. If affected, your BeaverTail will likely turn into a tale of bereavement, with your data and savings shaved into a pile of digital dust as you go bust. 

It has become significantly more sophisticated, moving beyond trojanized 'npm' packages to vectors such as fake recruitment platforms that trick victims into running OS‑specific commands and retains a modular architecture capable of harvesting system information, steal browser credentials, and cryptocurrency wallet data.

BeaverTail's sad tale almost sounds like the modern day equivalent of putting users into a hypnotic spell, a dark trance where victims unknowingly dance with the devil in the pale moonlight, running commands they would never otherwise type in voluntarily, all to enact their own data-laden doom - leaving not just a trace but a massive trail of destruction. That's dark. 

In early 2026, Darktrace will release its latest "State of Cybersecurity" report, where more information about the titillating tale of the BeaverTail will be told - amongst a range of other dark threats that loom like Daleks wanting to terminate our peace and prosperity - so keep safe over the festive season, and may Darktrace continue their efforts to go much deeper into threats like BeaverTail, whose 128 layers of concealment is a cover up of criminally epic proportions!

Read 3732 times

Please join our community here and become a VIP.

Subscribe to ITWIRE UPDATE Newsletter here
JOIN our iTWireTV our YouTube Community here
BACK TO LATEST NEWS here




Maximising Cloud Efficiency - LUMEN WEBINAR 23 April 2025

According to KPMG, companies typically spend 35% more on cloud than is required to deliver business objectives

The rush to the cloud has led to insufficient oversight, with many organisations struggling to balance the value of cloud agility and innovation against the need for guardrails to control costs.

Join us for an exclusive webinar on Cloud Optimisation.

In this event, the team from Lumen will explain how you can maximise cloud efficiency while reducing cost.

The session will reveal how to implement key steps for effective cloud optimisation.

Register for the event now!

REGISTER!

PROMOTE YOUR WEBINAR ON ITWIRE

It's all about Webinars.

Marketing budgets are now focused on Webinars combined with Lead Generation.

If you wish to promote a Webinar we recommend at least a 3 to 4 week campaign prior to your event.

The iTWire campaign will include extensive adverts on our News Site itwire.com and prominent Newsletter promotion https://itwire.com/itwire-update.html and Promotional News & Editorial. Plus a video interview of the key speaker on iTWire TV https://www.youtube.com/c/iTWireTV/videos which will be used in Promotional Posts on the iTWire Home Page.

Now we are coming out of Lockdown iTWire will be focussed to assisting with your webinars and campaigns and assistance via part payments and extended terms, a Webinar Business Booster Pack and other supportive programs. We can also create your adverts and written content plus coordinate your video interview.

We look forward to discussing your campaign goals with you. Please click the button below.

MORE INFO HERE!

BACK TO HOME PAGE
Alex Zaharov-Reutt

Alex Zaharov-Reutt is iTWire's Technology Editor. He is one of Australia’s best-known technology journalists and consumer tech experts,

Alex has appeared in his capacity as technology expert on all of Australia’s free-to-air and pay TV networks on all the major news and current affairs programs, on commercial and public radio, and technology, lifestyle and reality TV shows. 

You can listen to Alex on Canberra Radio 2CC every Saturday morning 10.30am to 11am local AEST/AEDT time at www.2cc.net.au, hear Alex weekly on ABC Radio Hobart www.abc.net.au/hobart at approximaltely 5.45pm AEST/AEDT, and on ABC Radio South East (Bega and surrounds) www.abc.net.au/southeastnsw every fortnight on Thursdays at 9.35am AEST/AEDT. 

Alex also presents a weekly tech segment with the "SpaceTime with Stuart Gary" podcast with 400,000 global downloads each month from spacetimewithstuartgary.com and the major podcast platforms. 

Alex's personal website is at www.techadvice.life, and he is a regular presenter on iTWire TV, available to view at www.youtube.com/iTWireTV

You can find Alex at X (formerly Twitter) here.

Share News tips for the iTWire Journalists? Your tip will be anonymous

WEBINARS & EVENTS

CYBERSECURITY

PEOPLE MOVES

GUEST ARTICLES

Guest Opinion

RESEARCH & CASE STUDIES

Channel News

Comments