Close Menu

    Subscribe to Updates

    What's Hot

    Pepe croaks as whale exodus deepens and buyers flinch

    June 7, 2025

    Beijing taps Hong Kong to liquidate seized crypto

    June 7, 2025

    Lagrange rockets, then reenters reality as hype fizzles

    June 7, 2025
    Facebook X (Twitter) Instagram
    laicryptolaicrypto
    Demo
    • Ethereum
    • Crypto
    • Altcoins
    • Blockchain
    • Bitcoin
    • Lithosphere News Releases
    laicryptolaicrypto
    Home Lazarus Group targets professionals with OtterCookie malware
    Crypto

    Lazarus Group targets professionals with OtterCookie malware

    John SmithBy John SmithJune 6, 2025No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    North Korea-linked hacking group Lazarus is reportedly using a new malware strain called OtterCookie to target people working in crypto and finance.

    According to a June 6 alert posted on X by web3 security firm SlowMist, the group is reportedly using fake job interviews, deepfake recruiter videos, and malware-laced coding challenges to deliver the stealer malware. OtterCookie can extract browser-stored credentials, macOS Keychain passwords, digital certificates, and private keys from crypto wallets.

    🚨SlowMist Security Alert🚨

    SlowMist recently received intelligence indicating that the Lazarus APT group is using a new stealer called OtterCookie in targeted attacks on crypto & finance pros.

    🎭Tactics:
    – Fake job interviews/investor calls
    – Deepfake videos to impersonate…

    — SlowMist (@SlowMist_Team) June 6, 2025

    It enables attackers to quietly steal confidential data from targeted systems, especially macOS machines. The tactic is gaining traction as attackers rely less on large-scale exploits and more on highly targeted, social-engineering-based methods.

    The latest malware appears to be part of Lazarus Group’s continuous efforts to penetrate the cryptocurrency industry. The group was responsible for February’s historic $1.5 billion Bybit hack, in which they obtained cold wallet signers through social engineering and spear phishing.

    In recent months, Lazarus has also launched npm package attacks aimed at developer environments and wallet infrastructure, including Solana (SOL) and Exodus. In April, the FBI and cybersecurity firm Silent Push seized a fake website used by Lazarus, known as “Blocknovas,” which posed as a U.S.-based tech company to deliver malware through job scams.

    According to SlowMist, crypto professionals should exercise caution when responding to unsolicited job or investment offers, particularly if they require downloading files or participating in video calls with strangers. Users should improve endpoint detection and response, refrain from running unknown binaries, and routinely check systems for unusual activity.

    So far this year, the crypto industry has taken the heaviest hit as a result of high-profile hacks. Q1 losses amounted to more than $1.6 billion, and the trend seems to be continuing. PeckShield estimates that losses from hacks totaled $244.1 million in May. Two significant events were the $220 million Cetus Protocol hack and another $12 million Cork Protocol exploit.





    Source link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    John Smith

    Related Posts

    Pepe croaks as whale exodus deepens and buyers flinch

    June 7, 2025

    Beijing taps Hong Kong to liquidate seized crypto

    June 7, 2025

    Lagrange rockets, then reenters reality as hype fizzles

    June 7, 2025
    Leave A Reply Cancel Reply

    Demo
    Don't Miss
    Crypto

    Pepe croaks as whale exodus deepens and buyers flinch

    By John SmithJune 7, 20250

    Pepe coin price retreated this week as whales continued selling and the crypto market sell-off…

    Beijing taps Hong Kong to liquidate seized crypto

    June 7, 2025

    Lagrange rockets, then reenters reality as hype fizzles

    June 7, 2025

    Unilabs Finance’s DeFi manager gains traction as top TradFi alternative, beating TRON, Solana

    June 7, 2025

    LAI Crypto is a user-friendly platform that empowers individuals to navigate the world of cryptocurrency trading and investment with ease and confidence.

    Our Posts
    • Altcoins (561)
    • Bitcoin (27)
    • Blockchain (134)
    • Crypto (8,310)
    • Ethereum (619)
    • Lithosphere News Releases (138)

    Subscribe to Updates

    • Twitter
    • Instagram
    • YouTube
    • LinkedIn

    Type above and press Enter to search. Press Esc to cancel.