OtterCandy is a Node.js-based, cross-platform remote-access trojan and information stealer targeting Windows, macOS, and Linux. It combines characteristics of OtterCookie and RATatouille and is used by the North Korea-linked WaterPlum threat actor, also tracked as Famous Chollima and PurpleBravo. Its deployment is particularly associated with WaterPlum’s Cluster B, commonly called the BlockNovas cluster. Samples were observed as early as February 2025, with cross-platform distribution documented from around July 2025.
OtterCandy communicates with command-and-control infrastructure through Socket.IO and accepts operator commands to search directories, locate files by patterns, collect system information, and exfiltrate browser credentials, cryptocurrency-wallet data, and sensitive files. Persistence is typically established by a preceding component named DiggingBeaver. OtterCandy also implements a self-restart mechanism that forks a replacement process when it receives a SIGINT signal. An update observed in late August 2025 improved victim identification, expanded targeted browser extensions, broadened Chromium user-data collection, and added cleanup behavior that removes persistence artifacts, files, and directories to conceal evidence of compromise.
The malware is distributed through fraudulent recruitment processes associated with the Contagious Interview and ClickFake Interview campaigns. Delivery mechanisms include malicious npm packages, coding assignments, and fake interview websites using ClickFix-style instructions or purported camera setup and driver updates. Targets include software developers, freelance IT professionals, and blockchain, cryptocurrency, and Web3 specialists, with activity observed in Japan and other regions. Its combination of remote access and information theft exposes developer credentials, cryptocurrency assets, and confidential project data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
OtterCandy Malware combining OtterCookie and RATatouille capabilities
18 distinct techniques documented for this family, organized by ATT&CK tactic.
WaterPlum actors upload malicious Node Package Manager (NPM) packages embedded with either BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle malware.
“Other sensitive data targeted for exfiltration includes… Clipboard information, key-logs (recorded keystrokes), screenshots.”
“Once a target is compromised, the attackers attempt to steal ... cryptocurrency private keys and seed phrases...”
The attackers obtained funds or account credentials from more than 7,000 cryptocurrency wallets... Stolen browser logins, wallet keys... can support further theft.
Targeted data includes “Any files or data of interest to the actors on a PC or in shared folders (ID pictures of driver’s licenses, passports, etc.).”
“Other sensitive data targeted for exfiltration includes… Clipboard information, key-logs (recorded keystrokes), screenshots.”
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malicious payload delivered through trojanized NPM packages in WaterPlum's fake-job-interview campaign. The content does not assign distinct capabilities to OtterCandy.
A malware family embedded in fake coding-test or troubleshooting downloads distributed by WaterPlum. It is part of the campaign's credential-, cryptocurrency-wallet-, and sensitive-data-theft operation.
A malware family delivered via fake recruitment and coding-test lures in the Contagious Interview campaign.
A malware payload embedded in packages used by the WaterPlum/Contagious Interview campaign against developers and IT professionals. It supports theft of credentials, sensitive data, and cryptocurrency-wallet material.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.