North Korean Cyber Group Overhauls OtterCookie Malware With Expanded Reach and Credential Theft Upgrades
A newly reinforced version of the OtterCookie malware, tied to the North Korean cyber-espionage group WaterPlum (also known as Famous Chollima or PurpleBravo), marks a notable leap in both functionality and platform reach. Originally flagged in September 2024, the malware has now entered a fourth iteration as of April 2025—underscoring the actor’s long-term strategic intent to compromise global financial ecosystems, including cryptocurrency platforms and FinTech firms.
WaterPlum’s tactical evolution has been closely charted, beginning with its “Contagious Interview” operation in 2023, where it initially leveraged BeaverTail before adopting OtterCookie in late 2024. This pivot signaled a recalibration of their offensive toolkit, favoring modular design and platform fluidity.
Security analysts at NTT Security, who have been persistently tracking WaterPlum’s digital footprint, report that OtterCookie has followed a steady two-to-three-month version cadence. The malware’s v3 and v4 editions remain actively deployed in ongoing campaigns, signaling parallel version usage—a rare tactic in advanced persistent threat (APT) playbooks.
The current version, OtterCookie v4, is architected to operate natively across Windows, Linux, and macOS environments, introducing specialized modules tailored for each OS. This cross-environment adaptability represents a marked departure from traditional malware, which often remains siloed to one operating system.
One of the most critical improvements in v4 lies in its advanced credential harvesting features. These new mechanisms are engineered to bypass conventional security layers, enabling more effective exfiltration of sensitive authentication data across enterprise environments.

Stealer Modules Reveal Layered Design Strategy in Latest OtterCookie Versions
(Reference: NTT Security)
The latest wave of OtterCookie variants—spanning versions 1 through 4—introduces a dual-pronged credential theft system that reflects both technical depth and operational diversity.
Embedded within these builds are purpose-specific modules engineered to harvest sensitive user data. One variant, tightly integrated with Windows systems, leverages the Data Protection API (DPAPI) to decrypt and extract saved credentials from Google Chrome. The credentials are then cached in a temporary local database file (\AppData\Local\1.db) to prepare for discreet exfiltration.
In contrast, a separate stealer module opts not to decrypt locally. Instead, it captures encrypted credential containers from Chrome, Brave, and the MetaMask browser extension, forwarding them in their encrypted form—potentially for offline decryption or further processing within attacker-controlled infrastructure.
This bifurcated architecture—combining real-time decryption with passive data collection—hints at a multi-developer operation behind OtterCookie, with potentially distinct teams focusing on different platforms or tactics. NTT Security’s analysis points to inconsistencies in coding style and logic paths as further evidence of collaborative or compartmentalized development.
Extending beyond Windows, the malware also probes Apple systems, attempting to extract credentials from macOS’s Keychain, reinforcing WaterPlum’s broader intent to infiltrate diverse enterprise and consumer environments.

Adaptive Evasion: OtterCookie’s Tactical Upgrades in Latest Builds
(Source: NTT Security)
The evolution of OtterCookie isn’t just about broader targeting—it’s about smarter survival. In its latest iterations, the malware exhibits an increasingly nuanced understanding of its execution environment, incorporating virtual machine awareness that enables it to detect sandbox analysis or security emulation. Upon identifying such conditions, it’s capable of modifying its runtime behavior, evading scrutiny and prolonging its presence on compromised systems.
Another quiet yet critical refinement lies in how OtterCookie monitors clipboard activity. By relying exclusively on built-in operating system utilities instead of invoking external libraries, it lowers its signature footprint and blends more seamlessly with normal system activity. This native-command approach significantly reduces its chances of being flagged by behavioral detection tools, underscoring the operators’ deliberate effort to sidestep conventional monitoring strategies.




