Additional Features of OtterCookie Malware Used by WaterPlum

2025-05-08 NTTSecurity

https://jp.security.ntt/tech_blog/en-waterplum-ottercookie

Thumbnail for Additional Features of OtterCookie Malware Used by WaterPlum

NTT analyzed updated OtterCookie malware used by WaterPlum, also tracked as Famous Chollima or PurpleBravo, against financial, cryptocurrency, and FinTech targets. The malware evolved from a file grabber into v3 and v4 variants with Windows support, hardcoded file-collection logic for documents, images, and cryptocurrency data, virtual-environment checks, and clipboard theft using macOS or Windows native commands. The stealer modules collect Chrome passwords through DPAPI, copy browser Login Data, and target MetaMask, Brave, and macOS credential material, with differing code styles suggesting separate module authors. Reported infrastructure includes alchemy-api-v3[.]cloud, chainlink-api-v3[.]cloud, and moralis-api-v3[.]cloud.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 188.116.26.84 2025-05-08 2026-02-19
IPv4 135.181.123.177 2025-04-11 2025-10-16
DOMAIN modilus.io 2025-05-08 2025-05-08
IPv4 65.108.122.31 2025-05-08 2025-05-08
IPv4 95.216.227.188 2025-05-08 2025-05-08
IPv4 65.21.23.63 2025-05-08 2025-05-08
IPv4 194.164.234.151 2025-05-08 2025-05-08
IPv4 116.202.208.125 2025-05-08 2025-05-08

Related Actors

Related Reports

« Back