Contagious Interview, a malware campaign targeting Mac users, has been identified by Jamf Threat Labs. The attackers utilize various delivery mechanisms, including disk images and packages disguised as legitimate software. These samples do not execute by default, suggesting either active testing or early development. The campaign uses the OtterCookie malware family, which includes a remote access trojan, credential stealer, in-memory filesystem scanner, and clipboard clipper. The attackers host their infrastructure on IP addresses 162.0.239[.]85 and 147.124.202[.]205.
Jamf Threat Labs continues to monitor this activity and track related infrastructure and variants, recommending customers configure threat prevention, advanced threat controls, and web protection in Jamf for Mac to block and report similar threats. The OtterCookie malware family consists of four components: a -based remote access trojan (scdata), browser/crypto wallet credential stealer (ldata), in-memory filesystem scanner, and in-memory clipboard clipper. The malware is hosted on 162.0.239[.]85 with the listener on port 3000.[/subscribe_to_unlock_form]
Contagious Interview, a malware campaign targeting Mac users, has been identified by Jamf Threat Labs. The attackers utilize various delivery mechanisms, including disk images and packages disguised as legitimate software. These samples do not execute by default, suggesting either active testing or early development. The campaign uses the OtterCookie malware family, which includes a remote access trojan, credential stealer, in-memory filesystem scanner, and clipboard clipper. The attackers host their infrastructure on IP addresses 162.0.239[.]85 and 147.124.202[.]205.
Jamf Threat Labs continues to monitor this activity and track related infrastructure and variants, recommending customers configure threat prevention, advanced threat controls, and web protection in Jamf for Mac to block and report similar threats. The OtterCookie malware family consists of four components: a -based remote access trojan (scdata), browser/crypto wallet credential stealer (ldata), in-memory filesystem scanner, and in-memory clipboard clipper. The malware is hosted on 162.0.239[.]85 with the listener on port 3000.[emaillocker id="1283"]
VirusTotal relations for this IP show a broader set of domains resolving to it. The operator server for OtterCookie is a separate host, 147.124.202[.]205, split across ports 7671, 7676, and 7679. This campaign shows signs that attackers may be testing different delivery mechanisms, as seen in the disk images and packages disguised as legitimate software. Contagious Interview continues to be a threat to Mac users as operators keep developing alternative methods for delivery.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.006 | Command and Scripting Interpreter | Python |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Anti-Behavioral Analysis | B0003 | Dynamic Analysis Evasion |
| Command & Control | B0030 | C2 Communication |
| Impact | B0022 | Remote Access |
| Discovery | E1083 | File and Directory Discovery |
The following reports contain further technical details:
[/emaillocker]