Developers Targeted by New ‘OtterCookie’ Malware with Fake Job Offers – Active IOCs

2024-12-27 Rewterz

https://www.rewterz.com/threat-advisory/developers-targeted-by-new-ottercookie-malware-with-fake-job-offers-active-iocs

Thumbnail for Developers Targeted by New ‘OtterCookie’ Malware with Fake Job Offers – Active IOCs

Rewterz reports that North Korean actors behind the Contagious Interview campaign are using OtterCookie malware in fake job-offer attacks against software developers. The campaign has operated since at least late 2022 and previously distributed BeaverTail and InvisibleFerret by luring developers into running malicious coding tests or project files. OtterCookie is described as a newer payload, active in the wild around November 2024, delivered through loaders that retrieve JSON data and execute JavaScript from a cookie field, including via Node.js projects, npm packages, and more recent Electron or Qt-style applications. Once running, OtterCookie uses Socket.IO WebSocket communications to reach C2 infrastructure and supports shell commands for reconnaissance and theft of documents, photos, cryptocurrency wallet data, and clipboard contents. The report lists active IOCs including domains, an IP address, and hashes tied to the OtterCookie activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d19ac8533ab14d97f4150973ffa810e… 2024-12-26 2025-02-03
HASH 32257fb11cc33e794fdfd0f952158a8… 2024-12-26 2025-02-03
HASH 4e0034e2bd5a30db795b73991ab659b… 2024-12-26 2025-02-03
HASH 7846a0a0aa90871f0503c430cc03488… 2024-12-26 2025-02-03
DOMAIN payloadrpc.com 2024-12-26 2025-02-03
IPv4 45.159.248.55 2024-12-26 2025-02-03

Related Actors

Related Reports

« Back