• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: North Korean Hacker Group Improves Malware Toolset by Merging BeaverTail and OtterCookie Functions
Share
  • bitcoinBitcoin(BTC)$68,785.00
  • ethereumEthereum(ETH)$2,039.61
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$639.47
  • rippleXRP(XRP)$1.41
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$85.55
  • tronTRON(TRX)$0.274640
  • dogecoinDogecoin(DOGE)$0.096185
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
News

North Korean Hacker Group Improves Malware Toolset by Merging BeaverTail and OtterCookie Functions

News Desk
Last updated: October 18, 2025 12:41 am
News Desk
Published: October 18, 2025
Share
malware code

A North Korean threat actor associated with the Contagious Interview campaign has been observed refining its malware toolkit by integrating functionalities from two distinct malware programs, BeaverTail and OtterCookie. This advancement was highlighted in findings by Cisco Talos, which reported that the most recent operations from the group show an increasing overlap between these two malware families. Notably, OtterCookie has received new enhancements, including modules for keylogging and taking screenshots.

The hacking activity is attributed to multiple aliases within the cybersecurity community, including CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, and others. In a striking development, Google Threat Intelligence Group (GTIG) and Mandiant have also identified the actor’s use of an advanced technique named EtherHiding. This method allows the group to fetch subsequent payloads from decentralized blockchain networks like the BNB Smart Chain and Ethereum, effectively transforming these decentralized infrastructures into resilient command-and-control servers. This tactic marks the first known instance of a nation-state operator employing EtherHiding, a strategy typically associated with cybercriminal organizations.

The Contagious Interview campaign itself first emerged around late 2022, characterized by North Korean hackers impersonating hiring organizations. Job seekers were duped into installing information-stealing malware under the guise of a technical assessment or coding task, leading to unauthorized access to sensitive data and cryptocurrencies.

In recent months, the campaign has evolved, incorporating ClickFix social engineering strategies to distribute various malware strains, including GolangGhost, PylangGhost, TsunamiKit, Tropidoor, and AkdoorTea. Central to these attacks are the malware families BeaverTail, OtterCookie, and InvisibleFerret. BeaverTail functions primarily as an information stealer and downloader, while OtterCookie, which was first detected in September 2024, was designed to communicate with remote servers to execute commands on compromised systems.

Cisco Talos reports that recent activity targeted an organization in Sri Lanka, which likely fell victim to a scam involving a fraudulent job offer that led to the installation of a malicious Node.js application named Chessfi, hosted on Bitbucket. The malicious application utilized a dependency from a package called “node-nvm-ssh,” which had previously been published on the official npm repository before being swiftly removed by the maintainers after attracting 306 downloads.

Upon installation, the malware leverages a postinstall hook in its configuration to execute a JavaScript payload that further loads additional scripts responsible for executing the final malware payload. Researchers noted that the latest iteration of OtterCookie demonstrates characteristics of both BeaverTail and OtterCookie, indicating a merging of their functionalities. This version introduces new modules such as a keylogger, a screenshotting feature, and an auxiliary clipboard monitoring capability, all relying on legitimate npm packages for their execution.

Additional functionalities present in the new iteration of OtterCookie include the ability to enumerate browser profiles and extensions, extract information from web browsers and cryptocurrency wallets, and install persistent remote access tools like AnyDesk. The malware also systematically searches the file system for valuable data related to cryptocurrencies and captures clipboard content for exfiltration to the threat actor’s command-and-control servers.

Talos also detected a Qt-based BeaverTail artifact and a malicious Visual Studio Code extension containing code from both BeaverTail and OtterCookie. This development raises questions about the group’s exploration of new malware delivery methods. Researchers suggested that the Visual Studio extension might be indicative of experimentation by another actor, who may not necessarily be connected to Famous Chollima, distinguishing it from the group’s typical tactics.

Round Six of the Wrangler National Finals Rodeo Delivers Thrilling Performances and Record-Breaking Moments
XRP Faces Significant Breakdown as Analysts Predict Price Drop Below $2
Bitcoin Price Faces Volatility as $90,000 Support Weakens
Hong Kong to List First Solana ETF on October 27
AMD Soars on OpenAI Partnership While AppLovin Faces SEC Inquiry
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article 06072f7f ff95 4af0 949b e4685d8c3e26 141526782.jpeg Tokenization Revolutionizes Financial Markets with Enhanced Transparency and Efficiency
Next Article 419b3e09371d4259892aeffffbe395d3 Top Stock Market Highlights of the Week: Genting Malaysia, Gold Prices and SGX-IDX Partnership
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
urlhttp3A2F2Fnpr brightspot.s3.amazonaws.com2Fba2F5b2F605f58664533b1794b2496ae0c6a2Fap24209
Trump’s Reelection Sparks Initial Crypto Surge Before Major Downturn
1760632538 news story
Chainlink Faces Downside Risks Amid Broader Crypto Market Bearish Phase
urlhttps3A2F2Fg.foolcdn.com2Feditorial2Fimages2F8500132Fcelebrating stock market success.jp
Broadcom’s AI Chip Strategy Could Elevate Its Market Presence by 2026
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Finance
  • Company
  • News
  • Stocks
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?