North Korea’s Famous Chollima APT Uses Trojanized Node.js App to Deploy OtterCookie RAT for Crypto Theft
ID: 27aa9d71-ba84-56dd-a80c-c810c9228ff4
STIX ID: report--27aa9d71-ba84-56dd-a80c-c810c9228ff4
Feed Name: securityonline.info
Cisco Talos describes a ‘Contagious Interview’ campaign by Famous Chollima that lures developers with fake job offers to install a trojanized Node.js project (Chessfi) or a malicious VS Code extension, delivering a merged BeaverTail/OtterCookie JavaScript malware suite that performs keylogging, screenshots, clipboard and browser/cryptocurrency wallet theft, file exfiltration, and remote shell access; the actors use NPM/Git supply-chain vectors, heavy obfuscation, and active C2 infrastructure (e.g., 172.86.88.188) to target developer systems across Windows, macOS, and Linux.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
