WaterPlumが使用するマルウェアOtterCookieの機能追加

2025-05-08 NTTSecurity Cyber threat report on ContagiousInterview, OtterCookie, WaterPlum

https://jp.security.ntt/tech_blog/waterplum-ottercookie

Thumbnail for WaterPlumが使用するマルウェアOtterCookieの機能追加

WaterPlum, also known as Famous Chollima or PurpleBravo, is described as a North Korea-linked actor targeting financial institutions, cryptocurrency businesses, and FinTech companies worldwide. The Japanese-language analysis says OtterCookie evolved from a file-grabbing v1 into later versions that support Windows, collect documents, images, cryptocurrency wallet data, and use hardcoded commands outside Windows environments. Newer modules add virtual-environment detection, clipboard theft using macOS or Windows standard commands, and credential theft from Chrome, Brave, MetaMask-related files, and macOS credential stores. The differing handling of decrypted and encrypted Chrome Login Data suggests separate module development, while listed infrastructure includes alchemy-api-v3[.]cloud, chainlink-api-v3[.]cloud, and moralis-api-v3[.]cloud.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 188.116.26.84 2025-05-08 2026-02-19
IPv4 135.181.123.177 2025-04-11 2025-10-16
DOMAIN modilus.io 2025-05-08 2025-05-08
IPv4 65.108.122.31 2025-05-08 2025-05-08
IPv4 95.216.227.188 2025-05-08 2025-05-08
IPv4 65.21.23.63 2025-05-08 2025-05-08
IPv4 194.164.234.151 2025-05-08 2025-05-08
IPv4 116.202.208.125 2025-05-08 2025-05-08

Related Actors

Related Reports

« Back