New ‘OtterCookie’ malware used to backdoor devs in fake job offers

Share:

North Korean threat actors are using new malware called OtterCookie in the Contagious Interview campaign that is targeting software developers.

Contagious Interview has been active since at least December 2022, according to researchers at cybersecurity company Palo Alto Networks. The campaign targets software developers with fake job offers to deliver malware such as BeaverTail and InvisibleFerret.

A report from NTT Security Japan notes that the Contagious Interview operation is now using a new piece of malware called OtterCookie, which was likely introduced in September and with a new variant appearing in the wild in November.

OtterCookie attack chain

Just like in the attacks documented by Palo Alto Networks’ Unit42 researchers, OtterCookie is delivered via a loader that fetches JSON data and executes the ‘cookie’ property as JavaScript code.

NTT says that, even though BeaverTail remains the most common payload, OtterCookie has been seen in some cases either deployed alongside BeaverTail or on its own.

The loader infects targets through Node.js projects or npm packages downloaded from GitHub or Bitbucket. However, files built as Qt or Electron applications were also used recently.

Overview of the latest Contagious Interview attacks
Overview of the latest Contagious Interview attacks
Source: NTT Japan

Once active on the target device, OtterCookie establishes secure communications with its command and control (C2) infrastructure using the Socket.IO WebSocket tool, and awaits for commands.

The researchers observed shell commands that perform data theft (e.g. collecting cryptocurrency wallet keys, documents, images, and other valuable information).

“The September version of OtterCookie already included a built-in functionality to steal keys related to cryptocurrency wallets,” NTT explains.

“For example, the checkForSensitiveData function used regular expressions to check for Ethereum private keys,” the researchers note, adding that this was changed with the November variant of the malware where this is achieved through remote shell commands.

The latest version of OtterCookie can also exfiltrate clipboard data to the threat actors, which may contain sensitive information.

Commands typically used for reconnaissance, like ‘ls’ and ‘cat’, were also detected, indicating the attacker’s intention to explore the environment and stage it for deeper infiltration or lateral movement.

The appearance of new malware and the diversification of the infection methods indicate that the threat actors behind the Contagious Interview campaign experiment with new tactics.

Software developers should try to verify information about a potential employer and be wary of running code on personal or work computers as part of a job offer that require coding tests.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:22 am, Jun 11, 2025
weather icon 14°C
L: 12° | H: 15°
broken clouds
Humidity: 80 %
Pressure: 1020 mb
Wind: 9 mph ENE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 81%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:16 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
12° | 15°°C 0 mm 0% 12 mph 83 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
14° | 25°°C 0.35 mm 35% 12 mph 77 % 1016 mb 0 mm/h
Fri Jun 13 10:00 pm
weather icon
16° | 27°°C 0.5 mm 50% 11 mph 86 % 1020 mb 0 mm/h
Sat Jun 14 10:00 pm
weather icon
17° | 23°°C 0.21 mm 21% 14 mph 90 % 1020 mb 0 mm/h
Sun Jun 15 10:00 pm
weather icon
13° | 22°°C 0.22 mm 22% 9 mph 85 % 1025 mb 0 mm/h
Today 4:00 am
weather icon
13° | 14°°C 0 mm 0% 5 mph 80 % 1020 mb 0 mm/h
Today 7:00 am
weather icon
14° | 15°°C 0 mm 0% 6 mph 83 % 1020 mb 0 mm/h
Today 10:00 am
weather icon
18° | 20°°C 0 mm 0% 7 mph 79 % 1021 mb 0 mm/h
Today 1:00 pm
weather icon
22° | 22°°C 0 mm 0% 8 mph 68 % 1020 mb 0 mm/h
Today 4:00 pm
weather icon
25° | 25°°C 0 mm 0% 11 mph 49 % 1018 mb 0 mm/h
Today 7:00 pm
weather icon
22° | 22°°C 0 mm 0% 12 mph 56 % 1017 mb 0 mm/h
Today 10:00 pm
weather icon
16° | 16°°C 0 mm 0% 10 mph 67 % 1017 mb 0 mm/h
Tomorrow 1:00 am
weather icon
15° | 15°°C 0 mm 0% 9 mph 70 % 1016 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€96,038.90
0.18%
Ethereum(ETH)
€2,439.07
3.85%
Tether(USDT)
€0.87
-0.03%
XRP(XRP)
€2.00
-1.05%
Solana(SOL)
€144.23
3.29%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.171251
0.94%
Shiba Inu(SHIB)
€0.000011
0.77%
Pepe(PEPE)
€0.000011
2.00%
Peanut the Squirrel(PNUT)
€0.253923
0.91%
Scroll to Top