North Korean Operators Target Developers with OtterCookie Malware on macOS

North Korean Operators Target Developers with OtterCookie Malware on macOS

First seen 4 Sep 2026, 21:27 UTC GbhackersSocprime 74.0

Article Content

Browse articles
ThreatCluster

A malware campaign identified by Jamf Threat Labs targets macOS developers using trojanized disk images and installer packages to deliver OtterCookie malware. The attackers, linked to North Korea, utilize fake job interview lures to trick victims into executing malicious code. The campaign involves a multi-stage execution chain that modifies Info.plist files in application bundles and PKG installers. Analysts found 14 malicious DMG and PKG samples impersonating legitimate software, ultimately delivering a JavaScript implant. Users are advised to avoid running unsigned applications and to isolate affected endpoints immediately. A forensic investigation is recommended to trace the initial delivery vector, which may include compromised Git repositories. The malware employs tools like Go-compiled shell scripts and the Bunster tool for deployment. Organizations can use Jamf for advanced threat controls to mitigate risks.

Key Points: • North Korean operators are using fake job interviews to deliver OtterCookie malware. • The attack targets macOS developers with trojanized applications and modified installer packages. • Users should avoid running unsigned applications and isolate infected systems immediately.

Ask AI about this cluster

Timeline

2026-09-04
Malware campaign identified
Jamf Threat Labs reported a new malware campaign delivering OtterCookie via trojanized macOS applications.
Socprime
2026-09-04
Malware delivery method detailed
The campaign uses fake job interviews to lure developers into executing malicious code through modified application bundles.
Gbhackers