216.73.216.6

Additional Features of OtterCookie Malware Used by WaterPlum

· Published 11/05/2025 05:05 · Modified 12/05/2025 09:19

Export JSON

Essential information

Published
11/05/2025 05:05
Modified
12/05/2025 09:19
Tags
2025-05-11 beavertail credential-theft cryptocurrency financial institutions invisibleferret macos north korea ottercookie stealer windows
Related entities
1 intrusion sets (apt), 9 techniques (mitre), 3 malware, 3 others

Description

The article discusses updates to the malware utilized by the -linked attack group WaterPlum. The malware has evolved through four versions, with v3 and v4 being the focus. v3 introduced support and enhanced file collection capabilities. Version 4 added new modules for credential theft, improved virtual environment detection, and modified clipboard stealing methods. The malware now targets various file types, including those related to cryptocurrencies, and has sophisticated methods for stealing browser credentials. The continuous updates to demonstrate WaterPlum's active development efforts, posing an ongoing threat to and operators worldwide.

External references