PULSE NAME
Additional Features of OtterCookie Malware Used by WaterPlum
WHITE WageMole AlienVault 2025-05-11 Modified: 2025-06-10
4
IOCs
LOW VOLUME
The article discusses updates to the OtterCookie malware utilized by the North Korea-linked attack group WaterPlum. The malware has evolved through four versions, with v3 and v4 being the focus. OtterCookie v3 introduced Windows support and enhanced file collection capabilities. Version 4 added new Stealer modules for credential theft, improved virtual environment detection, and modified clipboard stealing methods. The malware now targets various file types, including those related to cryptocurrencies, and has sophisticated methods for stealing browser credentials. The continuous updates to OtterCookie demonstrate WaterPlum's active development efforts, posing an ongoing threat to financial institutions and cryptocurrency operators worldwide.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
OtterCookie BeaverTail InvisibleFerret
Indicators of Compromise (4)
All domain
TYPEINDICATORDESCRIPTIONCREATED
domain alchemy-api-v3.cloud 2025-05-11
domain chainlink-api-v3.cloud 2025-05-11
domain modilus.io 2025-05-11
domain moralis-api-v3.cloud 2025-05-11