Hunting Lazarus Part VIII: OtterCookie
2026-05-16 • Red Asgard •
https://redasgard.com/blog/hunting-lazarus-part8-ottercookie
Red Asgard identifies OtterCookie as a separate JavaScript and Node.js RAT operating alongside BeaverTail and InvisibleFerret in Lazarus-linked Contagious Interview activity. Unlike BeaverTail’s stored-data theft model, OtterCookie uses Socket.IO over Engine.IO v4 to maintain live victim sessions, broadcast connected developer workstations on a timer, and support continuous surveillance. The collection profile includes clipboard monitoring, keystrokes, screenshots, browser secrets, wallet artifacts, `.env` files, SSH material, cloud credentials, and source-control tokens from active developer machines. The report also notes npm and Vercel delivery, public reporting of roughly 197 malicious packages, and campaign batch identifiers that should not be mistaken for hardware fingerprints.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 195.201.104.53 | 2026-02-28 | 2026-04-22 |
| DOMAIN | tetrismic.vercel.app | 2025-11-26 | 2025-11-26 |