Developers Targeted by New ‘OtterCookie’ Malware with Fake Job Offers – Active IOCs
2024-12-27 • Rewterz •
Rewterz reports that North Korean actors behind the Contagious Interview campaign are using OtterCookie malware in fake job-offer attacks against software developers. The campaign has operated since at least late 2022 and previously distributed BeaverTail and InvisibleFerret by luring developers into running malicious coding tests or project files. OtterCookie is described as a newer payload, active in the wild around November 2024, delivered through loaders that retrieve JSON data and execute JavaScript from a cookie field, including via Node.js projects, npm packages, and more recent Electron or Qt-style applications. Once running, OtterCookie uses Socket.IO WebSocket communications to reach C2 infrastructure and supports shell commands for reconnaissance and theft of documents, photos, cryptocurrency wallet data, and clipboard contents. The report lists active IOCs including domains, an IP address, and hashes tied to the OtterCookie activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ef13692228ee8e929c6e2e463b1ec30b | 2024-12-27 | 2025-02-03 |
| HASH | 9154c7d643e6d762dd1ab1df9125e4ea | 2024-12-27 | 2025-02-03 |
| HASH | 01abb0b0fff83bea08eef2a1bd8cb413 | 2024-12-27 | 2025-02-03 |
| HASH | 30ed90b4a570d6ff0c29759bfff491c2 | 2024-12-27 | 2025-02-03 |
| DOMAIN | payloadrpc.com | 2024-12-26 | 2025-02-03 |
| IPv4 | 45.159.248.55 | 2024-12-26 | 2025-02-03 |
| HASH | a94cef78aa9f22284c7e733680a1369… | 2024-12-27 | 2024-12-27 |
| HASH | 98746c50fc4aa656fe3a5747cc05eca… | 2024-12-27 | 2024-12-27 |
| HASH | 64c3b90c4093091c4cdedce4b7807dd… | 2024-12-27 | 2024-12-27 |
| HASH | 3630d9daeb501bf345299aacc710fd6… | 2024-12-27 | 2024-12-27 |
| HASH | 32257fb11cc33e794fdfd0f952158a8… | 2024-12-26 | 2024-12-27 |
| HASH | 7846a0a0aa90871f0503c430cc03488… | 2024-12-26 | 2024-12-27 |
| HASH | d19ac8533ab14d97f4150973ffa810e… | 2024-12-26 | 2024-12-27 |
| HASH | 4e0034e2bd5a30db795b73991ab659b… | 2024-12-26 | 2024-12-27 |