Threat Advisory

OtterCookie Malware Family Uses Multiple Components

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Contagious Interview, a malware campaign targeting Mac users, has been identified by Jamf Threat Labs. The attackers utilize various delivery mechanisms, including disk images and packages disguised as legitimate software. These samples do not execute by default, suggesting either active testing or early development. The campaign uses the OtterCookie malware family, which includes a remote access trojan, credential stealer, in-memory filesystem scanner, and clipboard clipper. The attackers host their infrastructure on IP addresses 162.0.239[.]85 and 147.124.202[.]205.

Jamf Threat Labs continues to monitor this activity and track related infrastructure and variants, recommending customers configure threat prevention, advanced threat controls, and web protection in Jamf for Mac to block and report similar threats. The OtterCookie malware family consists of four components: a -based remote access trojan (scdata), browser/crypto wallet credential stealer (ldata), in-memory filesystem scanner, and in-memory clipboard clipper. The malware is hosted on 162.0.239[.]85 with the listener on port 3000.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Contagious Interview, a malware campaign targeting Mac users, has been identified by Jamf Threat Labs. The attackers utilize various delivery mechanisms, including disk images and packages disguised as legitimate software. These samples do not execute by default, suggesting either active testing or early development. The campaign uses the OtterCookie malware family, which includes a remote access trojan, credential stealer, in-memory filesystem scanner, and clipboard clipper. The attackers host their infrastructure on IP addresses 162.0.239[.]85 and 147.124.202[.]205.

Jamf Threat Labs continues to monitor this activity and track related infrastructure and variants, recommending customers configure threat prevention, advanced threat controls, and web protection in Jamf for Mac to block and report similar threats. The OtterCookie malware family consists of four components: a -based remote access trojan (scdata), browser/crypto wallet credential stealer (ldata), in-memory filesystem scanner, and in-memory clipboard clipper. The malware is hosted on 162.0.239[.]85 with the listener on port 3000.[emaillocker id="1283"]

VirusTotal relations for this IP show a broader set of domains resolving to it. The operator server for OtterCookie is a separate host, 147.124.202[.]205, split across ports 7671, 7676, and 7679. This campaign shows signs that attackers may be testing different delivery mechanisms, as seen in the disk images and packages disguised as legitimate software. Contagious Interview continues to be a threat to Mac users as operators keep developing alternative methods for delivery.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.006 Command and Scripting Interpreter Python
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Anti-Behavioral Analysis B0003 Dynamic Analysis Evasion
Command & Control B0030 C2 Communication
Impact B0022 Remote Access
Discovery E1083 File and Directory Discovery

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu