Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagecredential-stealer-activitypackage-repository-poisoningcryptocurrency-platform-risk

North Korean Famous Chollima APT Deploys OtterCookie and BeaverTail Malware via Trojanized Node.js Apps for Cryptocurrency Theft

Updated 3mo agoFirst seen Oct 17, 20254 sources

The North Korean state-sponsored hacking group known as Famous Chollima has been identified as orchestrating a sophisticated cyber campaign targeting individuals and organizations with the goal of stealing cryptocurrency and sensitive credentials. Security researchers have observed that the group is leveraging trojanized Node.js applications, such as fake versions of legitimate apps like Chessfi, to deliver malicious payloads. Victims are lured through job scam tactics, where they are enticed to install what appears to be a legitimate application, but which actually contains hidden malware. The infection process involves the user executing an 'npm install' command, which surreptitiously downloads a malicious package named 'node-nvm-ssh.' This package is engineered to execute a series of obfuscated commands, ultimately deploying the OtterCookie and BeaverTail malware families onto the victim's system.

Recent analysis by Cisco Talos has revealed that the functionalities of BeaverTail and OtterCookie are being merged, indicating a strategic move by the attackers to streamline and enhance their toolset for future campaigns. The evolution of the OtterCookie malware has been particularly notable, with successive versions adding increasingly invasive capabilities. Early versions focused on stealing browser profiles, while later iterations introduced clipboard theft, file exfiltration from all mounted drives, and, most recently, advanced surveillance features. The latest version, designated V5, incorporates a keylogger to capture every keystroke and a screenshotting module that takes images of the victim's desktop every four seconds, with all collected data exfiltrated to the attackers' command and control infrastructure.

The campaign has been observed targeting high-value individuals and organizations, with at least one confirmed infection at a Sri Lanka-based organization. The attackers' use of legitimate-looking applications and sophisticated evasion techniques makes detection and prevention challenging. The campaign's primary objective appears to be the theft of cryptocurrency and sensitive user credentials, which are highly valuable on underground markets. Security experts warn that the merging of malware capabilities and the use of evolving infection vectors signal an ongoing and escalating threat from the Famous Chollima group. Organizations are advised to implement robust endpoint protection, monitor for suspicious npm package installations, and educate users about the risks of unsolicited job offers and software downloads. The campaign underscores the persistent and adaptive nature of North Korean cyber operations, particularly in their pursuit of financial gain through cybercrime.

Share:
North Korean Famous Chollima APT Deploys OtterCookie and BeaverTail Malware via Trojanized Node.js Apps for Cryptocurrency Theft
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Oct 20, 20258mo ago

Reporting identifies WaterPlum using Node.js OtterCandy RAT

A later report described a related North Korea-linked campaign attributed to WaterPlum that used a Node.js-based OtterCandy RAT for cryptocurrency theft and included an anti-forensic module, indicating continued evolution of this malware ecosystem.

Oct 16, 20258mo ago

Talos links campaign to broader DPRK fake-recruitment operations

Researchers connected the activity to North Korea's wider strategy of using job-themed lures and fake-company recruitment scams, consistent with earlier Lazarus Group-linked operations using the same malware families.

Researchers document expanded BeaverTail and OtterCookie capabilities

Talos said the malware toolset had evolved from browser-profile theft to broader credential and cryptocurrency theft, adding clipboard theft, file theft from mounted drives, keylogging, and frequent screenshot capture with exfiltration to command-and-control infrastructure.

Talos observes Sri Lanka infection via hidden npm package

In one observed case at an organization headquartered in Sri Lanka, a victim executed an npm install that fetched a concealed malicious package named "node-nvm-ssh," leading to BeaverTail and OtterCookie malware deployment.

Famous Chollima runs job-offer scam using trojanized apps

Cisco Talos reported that the North Korea-aligned group Famous Chollima used fake job offers to trick targets into installing trojanized applications such as "Chessfi," initiating infections through malicious Node.js packages.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

19 LINKEDOpen in app
Threat actors
1 linked
Affected products
3 linked
MetamaskTrust WalletMetamask
Organizations
11 linked
Cisco SystemsBinanceBrave SoftwareBlockNovas LLCLazarus GroupFamous ChollimaHackread.comMetamaskTrust WalletSilent PushGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.