Hunting Lazarus Part VIII: OtterCookie

2026-05-16 Red Asgard

https://redasgard.com/blog/hunting-lazarus-part8-ottercookie

Thumbnail for Hunting Lazarus Part VIII: OtterCookie

Red Asgard identifies OtterCookie as a separate JavaScript and Node.js RAT operating alongside BeaverTail and InvisibleFerret in Lazarus-linked Contagious Interview activity. Unlike BeaverTail’s stored-data theft model, OtterCookie uses Socket.IO over Engine.IO v4 to maintain live victim sessions, broadcast connected developer workstations on a timer, and support continuous surveillance. The collection profile includes clipboard monitoring, keystrokes, screenshots, browser secrets, wallet artifacts, `.env` files, SSH material, cloud credentials, and source-control tokens from active developer machines. The report also notes npm and Vercel delivery, public reporting of roughly 197 malicious packages, and campaign batch identifiers that should not be mistaken for hardware fingerprints.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 195.201.104.53 2026-02-28 2026-04-22
DOMAIN tetrismic.vercel.app 2025-11-26 2025-11-26

Related Actors

Related Reports

« Back