Additional Features of OtterCookie Malware Used by WaterPlum
2025-05-08 • NTTSecurity •
NTT analyzed updated OtterCookie malware used by WaterPlum, also tracked as Famous Chollima or PurpleBravo, against financial, cryptocurrency, and FinTech targets. The malware evolved from a file grabber into v3 and v4 variants with Windows support, hardcoded file-collection logic for documents, images, and cryptocurrency data, virtual-environment checks, and clipboard theft using macOS or Windows native commands. The stealer modules collect Chrome passwords through DPAPI, copy browser Login Data, and target MetaMask, Brave, and macOS credential material, with differing code styles suggesting separate module authors. Reported infrastructure includes alchemy-api-v3[.]cloud, chainlink-api-v3[.]cloud, and moralis-api-v3[.]cloud.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 188.116.26.84 | 2025-05-08 | 2026-02-19 |
| IPv4 | 135.181.123.177 | 2025-04-11 | 2025-10-16 |
| DOMAIN | modilus.io | 2025-05-08 | 2025-05-08 |
| IPv4 | 65.108.122.31 | 2025-05-08 | 2025-05-08 |
| IPv4 | 95.216.227.188 | 2025-05-08 | 2025-05-08 |
| IPv4 | 65.21.23.63 | 2025-05-08 | 2025-05-08 |
| IPv4 | 194.164.234.151 | 2025-05-08 | 2025-05-08 |
| IPv4 | 116.202.208.125 | 2025-05-08 | 2025-05-08 |