HomeSecurityChollima hackers combine BeaverTail and OtterCookie

Chollima hackers combine BeaverTail and OtterCookie

The Chollima, linked to North Korea's Reconnaissance General Bureau, has significantly expanded its operational capabilities by incorporating two powerful malware: BeaverTail and OtterCookie.

Chollima BeaverTail and OtterCookie

This convergence marks a critical evolution in the group's attack methodology, targeting the cryptocurrency and technology blockchain.

The merger of these tools reflects a deliberate shift towards JavaScript-based malware delivery, reducing reliance on Python while maintaining broad operational flexibility across multiple platforms and target profiles.

The group's latest campaign, tracked as Contagious Interview, exploits legitimate job search and recruitment channels to distribute trojanized.

See also: Qilin Ransomware combines Linux payload with BYOVD exploit

Recent discoveries reveal that organizations are experiencing breaches through seemingly innocent supply chain vectors, with a cryptocurrency-themed chess platform serving as an initial point of infection.

Chollima hackers combine BeaverTail and OtterCookie

The malicious payload infiltrated systems via dependency resolution, when developers cloned a Bitbucket repository for Chessfi, inadvertently pulling the compromised node-nvm-ssh package from public NPM repositories. This technique shows how operations credential theft seamlessly combine social engineering with supply chain exploitation techniques.

Polyswarm Threat Response Unit analysts discovered the unified malware architecture during investigations of a Sri Lanka-based breach, where post-install scripts executed obfuscated JavaScript payloads embedded in seemingly legitimate package dependencies.

The attack sequence revealed a sophisticated modular construct that combines the capabilities of BeaverTail and OtterCookie into a single information theft framework that targets cryptocurrency wallets and sensitive documents.

See also: Hackers steal Discord accounts via RedTiger

Technical Convergence and Capabilities

The integration of BeaverTail and OtterCookie represents a deliberate architectural unification rather than an accidental overlap. BeaverTail handles the initial reconnaissance, enumerating browser profiles and targeting cryptocurrency wallet extensions in Chrome, Brave and Edge browsers (specifically hunting for MetaMask, Phantom and Solflare installations).

The component downloads Python-based InvisibleFerret modules from command and control servers via port 1224, launching full Python distributions on Windows systems to enable full execution capabilities.

Chollima hackers combine BeaverTail and OtterCookie

OtterCookie complements this infrastructure through modular extensions that provide remote shell access via socket.io-client (for command execution and system fingerprinting, disk scanning for documents and credentials, and a dedicated cryptocurrency extension stealer that mirrors BeaverTail's wallet targeting logic).

See also: YouTube Ghost Network: 3,000 malicious videos distributed malware

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

A new keystroke logger module, first observed in April 2025, captures keystroke data and screen images, temporarily storing the extracted information in temporary files before transmitting it to the command infrastructure.

The malware implements analysis countermeasures, including context checks and error handling mechanisms for dynamic code execution.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS