Contagious Interviewが使用する新たなマルウェアOtterCookieについて
2024-12-26 • NTTSecurity • About the New OtterCookie Malware Used by Contagious Interview •
https://jp.security.ntt/tech_blog/contagious-interview-ottercookie
NTT Security Japan analyzes OtterCookie, a malware family observed in the Contagious Interview campaign, which is described as a North Korea-linked, financially motivated operation. The activity often begins with Node.js projects or npm packages downloaded from GitHub or Bitbucket, with some recent cases using Qt or Electron applications as the initial lure. OtterCookie was observed from November 2024 and may have been active since September 2024, with versions differing in implementation but sharing core capabilities. The malware supports remote shell commands, environment discovery, and collection of documents, images, cryptocurrency-related files, and wallet keys for exfiltration.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | payloadrpc.com | 2024-12-26 | 2025-02-03 |
| IPv4 | 45.159.248.55 | 2024-12-26 | 2025-02-03 |
| HASH | 32257fb11cc33e794fdfd0f952158a8… | 2024-12-26 | 2024-12-27 |
| HASH | 7846a0a0aa90871f0503c430cc03488… | 2024-12-26 | 2024-12-27 |
| HASH | d19ac8533ab14d97f4150973ffa810e… | 2024-12-26 | 2024-12-27 |
| HASH | 4e0034e2bd5a30db795b73991ab659b… | 2024-12-26 | 2024-12-27 |