logo

North Korea’s Famous Chollima APT Uses Trojanized Node.js App to Deploy OtterCookie RAT for Crypto Theft

ID: 27aa9d71-ba84-56dd-a80c-c810c9228ff4

STIX ID: report--27aa9d71-ba84-56dd-a80c-c810c9228ff4

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2025-10-17

Date Updated: 2026-04-22

Author: Ddos

...
...

Cisco Talos describes a ‘Contagious Interview’ campaign by Famous Chollima that lures developers with fake job offers to install a trojanized Node.js project (Chessfi) or a malicious VS Code extension, delivering a merged BeaverTail/OtterCookie JavaScript malware suite that performs keylogging, screenshots, clipboard and browser/cryptocurrency wallet theft, file exfiltration, and remote shell access; the actors use NPM/Git supply-chain vectors, heavy obfuscation, and active C2 infrastructure (e.g., 172.86.88.188) to target developer systems across Windows, macOS, and Linux.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.