PULSE NAME
OtterCookie Malware IOCs & Lazarus Distribution Infrastructure
WHITE Lazarus Group QuetzalTeam 2025-04-11 Modified: 2025-05-11
9
IOCs
LOW VOLUME
Contagious Interview is a cyberespionage campaign tracked by the Quetzal Team. We identified adversary infrastructure hosted in Finland, which serves as a malware delivery channel for OtterCookie. This intelligence pulse provides indicators of compromise (IOCs) for OtterCookie, along with detailed information about the distribution infrastructure used by the attackers. Additionally, we include the original repository where the loader is distributed, helping to track its propagation and identify potential victims. The loader is primarily distributed through LinkedIn, where the adversary creates fake profiles and posts fraudulent temporary job offers. These offers ask targets to download the loader and fix a supposed bug. Once the loader is executed, the infection begins.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
OtterCookie
Indicators of Compromise (1 / 9 total)
All FileHash-MD5 FileHash-SHA256 domain URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 56e15ef3b5e5f169fc063f8d3e88288e 2025-04-11