DiggingBeaver is a malware component used by the North Korea-linked threat group WaterPlum, also known as Famous Chollima or PurpleBravo, in activity associated with the ClickFake Interview campaign and its Cluster B / BlockNovas operations. The provided reporting describes DiggingBeaver as a prerequisite tool that establishes persistence for the later-stage OtterCandy malware. OtterCandy typically relies on the preceding DiggingBeaver component for initial persistence, after which OtterCandy can continue with RAT and information-stealing functions. The content does not provide standalone technical details for DiggingBeaver’s own capabilities, infection vector, supported platforms, or specific indicators of compromise beyond its role as the persistence-enabling precursor in this intrusion chain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DiggingBeaver is a tool used to maintain persistence on compromised systems as part of the OtterCandy malware campaign.
Referenced as a preceding component used to establish initial persistence before OtterCandy execution; no additional functional details provided in the content.
OtterCandyの前段として用いられ、永続化を実施するコンポーネント/マルウェアとして言及されている。
"OtterCandy achieves persistence by the preceding DiggingBeaver..."
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.