TF-MAL-js.otter_cookie
📛 Threat Title
Malware family: OtterCookie
Description
ThreatFox malware family `js.otter_cookie`. Printable name: OtterCookie.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:any.run
Explore in-depth technical analysis of OtterCookie , a new North Korean Lazarus APT malware that steals victims' crypto and credentials.
-
web:anyrun.substack.com
Overview of OtterCookie Malware North Korean state-sponsored groups, most notably Lazarus, continue to target the financial and cryptocurrency sectors using a range of custom malware families.
-
web:blackpointcyber.com
The Blackpoint SOC recently contained an incident involving OtterCookie , a North Korean linked malware family delivered through a trojanized Node module.
-
web:lazarus.day
OtterCookie , a new tool from the Lazarus Group APT, hides behind clean code and fake job offers, then silently steals credentials, crypto wallets, and more. In this step-by-step technical analysis, Mauro Eldritch breaks down the full attack chain, supported by live insights from ANY.RUN's Interactive Sandbox.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the OtterCookie malware family including references, samples and yara signatures.
-
web:medium.com
Overview of OtterCookie Malware North Korean state-sponsored groups, most notably Lazarus, continue to target the financial and cryptocurrency sectors using a range of custom malware families.
-
web:thehackernews.com
OtterCookie v4 adds VM evasion and MetaMask theft in April 2025, signaling rapid malware evolution.
-
web:threatprophet.com
Analysis of a Contagious Interview campaign delivering an OtterCookie - family three-child loader via a Bitbucket skill-test lure, targeting developer credentials, cryptocurrency wallets, and 2FA seeds across all major platforms.
-
web:www.linkedin.com
OtterCookie is a JavaScript/Node.js backdoor-infostealer tied to the North Korea-linked Contagious Interview / DeceptiveDevelopment activity cluster.
-
web:www.thaicert.or.th
The attackers have uploaded over 197 malicious npm packages into the developer ecosystem, using them to distribute a new malware family dubbed " OtterCookie ." The campaign continues to target software developers-particularly those working in crypto, Web3, and blockchain-across Windows, Linux, and macOS.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.