OtterCookie, new malware used in Contagious Interview campaign

2024-12-26 NTTSecurity

https://jp.security.ntt/tech_blog/en-contagious-interview-ottercookie

Thumbnail for OtterCookie, new malware used in Contagious Interview campaign

NTT's SOC identified OtterCookie as malware used in the North Korea-linked Contagious Interview campaign, with activity observed around November 2024 and possible use since September. The campaign commonly starts from Node.js projects, npm packages or files embedded in Qt or Electron applications, reflecting continued experimentation with developer-focused lures. The November OtterCookie variant uses Socket.IO to communicate with a remote host, supports shell-command execution through a command function and host profiling through whour, and can send local clipboard contents with the clipboardy library. Analysts observed commands that searched documents, pictures and cryptocurrency-related files for wallet keys, making the malware relevant to DPRK crypto-theft tracking.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN payloadrpc.com 2024-12-26 2025-02-03
IPv4 45.159.248.55 2024-12-26 2025-02-03
HASH 32257fb11cc33e794fdfd0f952158a8… 2024-12-26 2024-12-27
HASH 7846a0a0aa90871f0503c430cc03488… 2024-12-26 2024-12-27
HASH d19ac8533ab14d97f4150973ffa810e… 2024-12-26 2024-12-27
HASH 4e0034e2bd5a30db795b73991ab659b… 2024-12-26 2024-12-27

Related Actors

Related Reports

« Back