Listen to this Post

The Rise of a Cyber Predator
In the ever-evolving world of cyber warfare, few actors have demonstrated persistence and technical agility like Famous Chollima — a North Korean state-aligned hacking group known for its precision attacks on the global cryptocurrency and blockchain sectors. In 2025, the group took a bold step forward, merging two of its notorious malware strains, BeaverTail and OtterCookie, into a new, unified infostealer that blends stealth, intelligence, and devastation.
What makes this campaign especially dangerous is its sophistication. The hackers are now disguising their operations behind fake job offers, trojanized developer packages, and corrupted repositories — exploiting human trust and software ecosystems in equal measure. Their latest weapon: a cryptocurrency-themed chess app called Chessfi, secretly built to deliver one of the most advanced digital espionage tools ever linked to North Korea’s Reconnaissance General Bureau (RGB).
When a Game Becomes a Trap
The new campaign’s infection chain begins innocently. Developers and crypto professionals encounter Chessfi — an open-source project hosted on a compromised Bitbucket repository. When they clone it, hidden dependencies automatically pull a malicious NPM package, node-nvm-ssh, into their system. This package runs concealed JavaScript payloads that execute in the background, embedding malware into trusted environments.
Unlike traditional phishing attacks, this vector manipulates the trust developers place in open-source ecosystems. It bypasses the user’s caution and directly infiltrates development workflows. Once activated, the malware silently merges functionalities from both BeaverTail and OtterCookie — two previously distinct families now fused into a hybrid capable of total system compromise.
BeaverTail focuses on browser-based reconnaissance. It hunts through Chromium-based browsers like Chrome, Brave, and Edge, extracting wallet data from extensions such as MetaMask, Phantom, and Solflare. It also communicates with remote command servers through unusual ports (like 1224), ensuring persistent access and cross-system compatibility by automatically installing Python environments when needed.
Meanwhile, OtterCookie extends the infection’s reach with remote shell access, data exfiltration, and system fingerprinting. It adds stealth functions, scanning for sensitive documents and crypto wallets while strategically avoiding directories that might trigger antivirus alarms.
In April 2025, researchers detected a new OtterCookie module with built-in keylogging, screenshot capture, and clipboard monitoring. These capabilities allow Famous Chollima to collect passwords, seed phrases, and two-factor authentication codes from unsuspecting victims. On macOS, the malware leverages “pbpaste,” while on Windows, it uses PowerShell scripts — a perfect example of how this threat adapts across environments.
Malware That Learns, Evolves, and Hides
Over the past year, OtterCookie has evolved through five distinct versions, each iteration introducing new defenses against detection. The fifth version, rolled out in August 2025, incorporates environmental awareness: it checks whether it’s running in a virtualized sandbox and deploys dynamic code loading only when safe. Early builds transmitted payloads through simple HTTP cookies, but modern ones use modular, string-based executions — making them harder to detect by traditional network monitors.
BeaverTail followed a similar evolutionary path. Since mid-2023, it has employed obfuscation tricks like Base64-shuffled C2 URLs and modularized cross-platform execution. This adaptability explains why both malware strains are being integrated into supply chain attacks targeting developers, blockchain projects, and cryptocurrency startups.
Together, they form an ecosystem — a malware symphony — tuned to harvest financial intelligence while feeding the DPRK’s state coffers.
North Korea’s Cyber Chess Game
Famous Chollima, a subset of the broader Lazarus Group umbrella, operates under several aliases, including Wagemole, Nickel Tapestry, and UNC5267. Since at least 2018, it has conducted a series of social engineering campaigns known as Contagious Interviews, impersonating recruiters from major tech companies to trick professionals into downloading infected files disguised as technical assessments.
The current Chessfi operation mirrors this tactic but takes it further by embedding malware in developer tools — turning supply chains themselves into attack vectors. The group’s targets remain consistent: cryptocurrency exchanges, blockchain startups, and high-value fintech sectors across the United States, India, Germany, and Ukraine.
The ultimate goal is clear: to bypass international sanctions by stealing digital assets and hard currency through cybertheft. For the DPRK regime, this is not just espionage — it’s survival economics.
Indicators of Compromise (IOCs)
Security firm PolySwarm has identified multiple samples connected to this activity, including the following SHA256 hashes:
caad2f3d85e467629aa535e0081865d329c4cd7e6ff20a000ea07e62bf2e4394
83c145aedfdf61feb02292a6eb5091ea78d8d0ffaebf41585c614723f36641d8
Researchers warn that these indicators could appear in systems that have downloaded infected NPM packages or cloned compromised repositories.
What Undercode Say:
Famous Chollima’s latest evolution is not just a technical milestone; it’s a psychological operation wrapped in software. The strategic merger of BeaverTail and OtterCookie reveals a new doctrine in North Korean cyber warfare — one focused on stealth infiltration rather than brute-force attacks.
By exploiting the credibility of developer platforms like NPM and Bitbucket, Chollima effectively bypasses the most common line of defense: human suspicion. The move from phishing emails to supply-chain manipulation signals a recognition that the real battleground is trust itself.
From a cybersecurity perspective, this is a paradigm shift. Supply chain compromises were once the domain of highly resourced Western intelligence agencies. Now, North Korea is weaponizing them to sustain its regime economically, using stolen digital wealth to offset sanctions.
The modular design of the malware family also demonstrates an industrial approach to cybercrime. Each new variant builds on the previous generation’s success, using versioning and dynamic execution methods reminiscent of legitimate software development. This hybridization not only improves persistence but also complicates attribution, making it harder for security researchers to link attacks conclusively to specific actors.
Another crucial insight lies in the group’s selective targeting. By focusing on blockchain developers, crypto investors, and fintech professionals, Chollima ensures access to digital assets that are anonymous, decentralized, and nearly impossible to recover once stolen. The attackers have learned that in crypto heists, speed and silence are everything — and Chessfi provides both.
The evolution of OtterCookie’s sandbox evasion and dynamic loading indicates a deliberate response to modern cybersecurity tooling. Where traditional malware relied on brute persistence, Chollima’s code now thinks before it acts, analyzing its environment before revealing itself. This adaptive intelligence makes it one of the hardest threats to contain in modern cybersecurity landscapes.
In essence, Famous Chollima is not just building malware — it’s building a system of digital mimicry, one capable of living undetected in trusted environments while quietly feeding stolen data to state-controlled operators. This is not a lone cybercrime incident; it’s a sign of a maturing, state-backed digital economy built on global theft.
For organizations in the blockchain and tech industries, this is a wake-up call. Every dependency, every repository, every piece of code you trust could be a Trojan horse. The new war is not waged through firewalls but through faith in open-source software — and Chollima has just proven that faith can be manipulated.
🔍 Fact Checker Results
✅ Famous Chollima is a verified DPRK-linked threat actor tied to the Reconnaissance General Bureau.
✅ The Chessfi campaign and merged malware functionalities are confirmed by multiple cybersecurity firms.
❌ There is no public evidence yet that this campaign has caused large-scale cryptocurrency theft, though potential remains high.
📊 Prediction
🧠 Expect North Korea’s cyber units to continue merging and modularizing malware families, reducing detection and boosting persistence.
💰 Cryptocurrency and blockchain projects will remain prime targets through 2026 as Chollima focuses on financial theft for regime funding.
⚙️ Future variants may extend to macOS and Linux developer ecosystems, embedding deeper into supply chains and open-source libraries.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.medium.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




