WaterPlumが使用するマルウェアOtterCookieの機能追加
2025-05-08 • NTTSecurity • Cyber threat report on ContagiousInterview, OtterCookie, WaterPlum •
WaterPlum, also known as Famous Chollima or PurpleBravo, is described as a North Korea-linked actor targeting financial institutions, cryptocurrency businesses, and FinTech companies worldwide. The Japanese-language analysis says OtterCookie evolved from a file-grabbing v1 into later versions that support Windows, collect documents, images, cryptocurrency wallet data, and use hardcoded commands outside Windows environments. Newer modules add virtual-environment detection, clipboard theft using macOS or Windows standard commands, and credential theft from Chrome, Brave, MetaMask-related files, and macOS credential stores. The differing handling of decrypted and encrypted Chrome Login Data suggests separate module development, while listed infrastructure includes alchemy-api-v3[.]cloud, chainlink-api-v3[.]cloud, and moralis-api-v3[.]cloud.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 188.116.26.84 | 2025-05-08 | 2026-02-19 |
| IPv4 | 135.181.123.177 | 2025-04-11 | 2025-10-16 |
| DOMAIN | modilus.io | 2025-05-08 | 2025-05-08 |
| IPv4 | 65.108.122.31 | 2025-05-08 | 2025-05-08 |
| IPv4 | 95.216.227.188 | 2025-05-08 | 2025-05-08 |
| IPv4 | 65.21.23.63 | 2025-05-08 | 2025-05-08 |
| IPv4 | 194.164.234.151 | 2025-05-08 | 2025-05-08 |
| IPv4 | 116.202.208.125 | 2025-05-08 | 2025-05-08 |