Interview with the Chollima
2025-04-11 • Bitso •
Bitso’s Quetzal team describes a highly targeted North Korean Chollima/Lazarus social-engineering attempt against fintech and crypto personnel. A fake recruiter using the name “Wilton Santos” asked the researcher to patch a DApp repository, but the apparently clean code contained a failing bootstrap path whose catch handler pulled code from an external API and executed it via require. Sandbox execution showed the payload was OtterCookie, a stealer associated with ContagiousInterview that targets browser password managers and crypto-wallet extensions. The report links the activity to broader tactics used against engineers through fake coding tasks and against executives through fake Zoom-fix lures. Listed indicators include chainlink-api-v3.cloud, 135.181.123.177, a Bitbucket download URL, several SHA256 hashes, and a Solana wallet address.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | chainlink-api-v3.cloud | 2025-04-11 | 2026-02-19 |
| IPv4 | 135.181.123.177 | 2025-04-11 | 2025-10-16 |
| HASH | 56e15ef3b5e5f169fc063f8d3e88288e | 2025-04-11 | 2025-07-30 |
| URL | http://chainlink-api-v3.cloud/a… | 2025-04-11 | 2025-07-30 |
| HASH | ec234419fc512baded05f7b29fefbf1… | 2025-04-11 | 2025-06-03 |
| HASH | aa0d64c39680027d56a32ffd4ceb787… | 2025-04-11 | 2025-06-03 |
| HASH | 071aff6941dc388516d8ca0215b757f… | 2025-04-11 | 2025-06-03 |
| HASH | 486f305bdd09a3ef6636e92c6a9e016… | 2025-04-11 | 2025-06-03 |
| URL | http://chainlink-api-v3.cloud/a… | 2025-04-11 | 2025-06-03 |