logo

New 'OtterCookie' malware used to backdoor devs in fake job offers

ID: b1386743-bdce-5396-951c-ba110f3e0d2e

STIX ID: report--b1386743-bdce-5396-951c-ba110f3e0d2e

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-12-26

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

North Korean operators running the ‘Contagious Interview’ campaign are targeting software developers with fake job offers and malicious Node.js/npm/Qt/Electron artifacts to deliver a new loader called OtterCookie. Introduced around September with a variant in November, OtterCookie uses Socket.IO for C2, executes remotely supplied JavaScript, and enables reconnaissance and exfiltration (including cryptocurrency private keys and clipboard data); it has been observed alongside BeaverTail and InvisibleFerret payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.