Developers Targeted by New ‘OtterCookie’ Malware with Fake Job Offers – Active IOCs

2024-12-27 Rewterz

https://www.rewterz.com/threat-advisory/developers-targeted-by-new-ottercookie-malware-with-fake-job-offers-active-iocs

Thumbnail for Developers Targeted by New ‘OtterCookie’ Malware with Fake Job Offers – Active IOCs

Rewterz reports that North Korean actors behind the Contagious Interview campaign are using OtterCookie malware in fake job-offer attacks against software developers. The campaign has operated since at least late 2022 and previously distributed BeaverTail and InvisibleFerret by luring developers into running malicious coding tests or project files. OtterCookie is described as a newer payload, active in the wild around November 2024, delivered through loaders that retrieve JSON data and execute JavaScript from a cookie field, including via Node.js projects, npm packages, and more recent Electron or Qt-style applications. Once running, OtterCookie uses Socket.IO WebSocket communications to reach C2 infrastructure and supports shell commands for reconnaissance and theft of documents, photos, cryptocurrency wallet data, and clipboard contents. The report lists active IOCs including domains, an IP address, and hashes tied to the OtterCookie activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ef13692228ee8e929c6e2e463b1ec30b 2024-12-27 2025-02-03
HASH 9154c7d643e6d762dd1ab1df9125e4ea 2024-12-27 2025-02-03
HASH 01abb0b0fff83bea08eef2a1bd8cb413 2024-12-27 2025-02-03
HASH 30ed90b4a570d6ff0c29759bfff491c2 2024-12-27 2025-02-03
DOMAIN payloadrpc.com 2024-12-26 2025-02-03
IPv4 45.159.248.55 2024-12-26 2025-02-03
HASH a94cef78aa9f22284c7e733680a1369… 2024-12-27 2024-12-27
HASH 98746c50fc4aa656fe3a5747cc05eca… 2024-12-27 2024-12-27
HASH 64c3b90c4093091c4cdedce4b7807dd… 2024-12-27 2024-12-27
HASH 3630d9daeb501bf345299aacc710fd6… 2024-12-27 2024-12-27
HASH 32257fb11cc33e794fdfd0f952158a8… 2024-12-26 2024-12-27
HASH 7846a0a0aa90871f0503c430cc03488… 2024-12-26 2024-12-27
HASH d19ac8533ab14d97f4150973ffa810e… 2024-12-26 2024-12-27
HASH 4e0034e2bd5a30db795b73991ab659b… 2024-12-26 2024-12-27

Related Actors

Related Reports

« Back