talos · Crawled Jul 25, 2026
BeaverTail and OtterCookie evolve with a new Javascript module
26 IoCs 1 Actors 4 Malware
Read original article ↗
AI Summary
Cisco Talos identified a new attack campaign linked to the DPRK-aligned threat group Famous Chollima, which uses social engineering through fake job offers to distribute trojanized Node.js applications. The campaign leverages malicious npm packages like 'node-nvm-ssh' and combines the BeaverTail and OtterCookie malware tools to steal credentials, cryptocurrency wallets, and system information. Recent evolution includes merged functionality between BeaverTail and OtterCookie, with new capabilities such as keylogging, screenshot capture, and clipboard monitoring delivered via a modular JavaScript-based framework.
AI-extracted · verify before operational use
Extracted Entities 5 found
Indicators of Compromise 26 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 172[.]86[.]88[.]188 | Details → |
| IP | 23[.]227[.]202[.]244 | Details → |
| IP | 138[.]201[.]50[.]5 | Details → |
| IP | 135[.]181[.]123[.]177 | Details → |
| IP | 144[.]172[.]96[.]35 | Details → |
| IP | 144[.]172[.]112[.]50 | Details → |
| IP | 172[.]86[.]73[.]46 | Details → |
| IP | 172[.]86[.]113[.]12 | Details → |
| Domain | bitbucket[.]org | Details → |
| Package | node-nvm-ssh | Details → |
| Filename | test.list | Details → |
| Filename | raw.js | Details → |
| SHA-256 | f08e3ee84714cc5faefb7ac300485c879356922003d667587c58d594d875294e | Details → |
| SHA-256 | 72ebfe69c69d2dd173bb92013ab44d895a3367f91f09e3f8d18acab44e37b26d | Details → |
| SHA-256 | caad2f3d85e467629aa535e0081865d329c4cd7e6ff20a000ea07e62bf2e4394 | Details → |
| SHA-256 | 8efa928aa896a5bb3715b8b0ed20881029b0a165a296334f6533fa9169b4463b | Details → |
| SHA-256 | 83c145aedfdf61feb02292a6eb5091ea78d8d0ffaebf41585c614723f36641d8 | Details → |
| SHA-256 | 77aec48003beeceb88e70bed138f535e1536f4bbbdff580528068ad6d184f379 | Details → |
| SHA-256 | 0904eff1edeff4b6eb27f03e0ccc759d6aa8d4e1317a1e6f6586cdb84db4a731 | Details → |
| SHA-256 | d27c9f75c3f1665ee19642381a4dd6f2e4038540442cf50948b43f418730fd0a | Details → |
| SHA-256 | 51ddd8f6ff30d76de45e06902c45c55163ddbec7d114ad89b21811ffedb71974 | Details → |
| SHA-256 | d89c45d65a825971d250d12bc7a449321e1977f194e52e4ca541e8a908712e47 | Details → |
| SHA-256 | 6a9b4e8537bb97e337627b4dd1390bdb03dc66646704bd4b68739d499bd53063 | Details → |
| SHA-256 | a6914ded72bdd21e2f76acde46bf92b385f9ec6f7e6b7fdb873f21438dfbff1d | Details → |
| SHA-256 | 9e65de386b40f185bf7c1d9b1380395e5ff606c2f8373c63204a52f8ddc01982 | Details → |
| SHA-256 | dff2a0fb344a0ad4b2c129712b2273fda46b5ea75713d23d65d5b03d0057f6dd | Details → |
MITRE ATT&CK TTPs 22 techniques
T1005 Data from Local System · Collection T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1113 Screen Capture · Collection T1114 Email Collection · Collection T1123 Audio Capture · Collection T1482 Domain Trust Discovery · Discovery T1490 Inhibit System Recovery · Impact T1555 Credentials from Password Stores · Credential Access T1566 Phishing · Initial Access T1003 OS Credential Dumping · Credential Access T1056.002 GUI Input Capture · Collection T1059.007 JavaScript · Execution T1071 Application Layer Protocol · Command And Control T1195.002 Compromise Software Supply Chain · Initial Access T1110 Brute Force · Credential Access