OtterCookie, new malware used in Contagious Interview campaign
2024-12-26 • NTTSecurity •
https://jp.security.ntt/tech_blog/en-contagious-interview-ottercookie
NTT's SOC identified OtterCookie as malware used in the North Korea-linked Contagious Interview campaign, with activity observed around November 2024 and possible use since September. The campaign commonly starts from Node.js projects, npm packages or files embedded in Qt or Electron applications, reflecting continued experimentation with developer-focused lures. The November OtterCookie variant uses Socket.IO to communicate with a remote host, supports shell-command execution through a command function and host profiling through whour, and can send local clipboard contents with the clipboardy library. Analysts observed commands that searched documents, pictures and cryptocurrency-related files for wallet keys, making the malware relevant to DPRK crypto-theft tracking.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | payloadrpc.com | 2024-12-26 | 2025-02-03 |
| IPv4 | 45.159.248.55 | 2024-12-26 | 2025-02-03 |
| HASH | 32257fb11cc33e794fdfd0f952158a8… | 2024-12-26 | 2024-12-27 |
| HASH | 7846a0a0aa90871f0503c430cc03488… | 2024-12-26 | 2024-12-27 |
| HASH | d19ac8533ab14d97f4150973ffa810e… | 2024-12-26 | 2024-12-27 |
| HASH | 4e0034e2bd5a30db795b73991ab659b… | 2024-12-26 | 2024-12-27 |