Interview with the Chollima

2025-04-11 Bitso

https://quetzal.bitso.com/p/interview-with-the-chollima

Thumbnail for Interview with the Chollima

Bitso’s Quetzal team describes a highly targeted North Korean Chollima/Lazarus social-engineering attempt against fintech and crypto personnel. A fake recruiter using the name “Wilton Santos” asked the researcher to patch a DApp repository, but the apparently clean code contained a failing bootstrap path whose catch handler pulled code from an external API and executed it via require. Sandbox execution showed the payload was OtterCookie, a stealer associated with ContagiousInterview that targets browser password managers and crypto-wallet extensions. The report links the activity to broader tactics used against engineers through fake coding tasks and against executives through fake Zoom-fix lures. Listed indicators include chainlink-api-v3.cloud, 135.181.123.177, a Bitbucket download URL, several SHA256 hashes, and a Solana wallet address.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN chainlink-api-v3.cloud 2025-04-11 2026-02-19
IPv4 135.181.123.177 2025-04-11 2025-10-16
HASH 56e15ef3b5e5f169fc063f8d3e88288e 2025-04-11 2025-07-30
URL http://chainlink-api-v3.cloud/a… 2025-04-11 2025-07-30
HASH ec234419fc512baded05f7b29fefbf1… 2025-04-11 2025-06-03
HASH aa0d64c39680027d56a32ffd4ceb787… 2025-04-11 2025-06-03
HASH 071aff6941dc388516d8ca0215b757f… 2025-04-11 2025-06-03
HASH 486f305bdd09a3ef6636e92c6a9e016… 2025-04-11 2025-06-03
URL http://chainlink-api-v3.cloud/a… 2025-04-11 2025-06-03

Related Actors

Related Reports

« Back