OtterCandy is a cross-platform, Node.js-based remote-access trojan and information stealer associated with the North Korea-linked WaterPlum threat actor, also tracked as Famous Chollima and PurpleBravo. It has been used by WaterPlum Cluster B, known as BlockNovas, in the ClickFake Interview campaign since at least 2025. The malware combines characteristics associated with OtterCookie and RATatouille and targets Windows, macOS, and Linux systems.
OtterCandy communicates with command-and-control infrastructure through Socket.IO and accepts operator commands for remote collection activity. Its supported theft functions include collecting browser credentials, cryptocurrency-wallet data, system information, and sensitive files. It can sweep user directories and search for files matching specified patterns. Later variants expanded browser-extension targeting and altered Chromium data collection to exfiltrate complete user-data content rather than limited subsets.
OtterCandy generally follows a preceding DiggingBeaver component that establishes persistence, while the malware also includes a self-restart mechanism that re-forks its process after an interrupt signal. Updated variants include anti-forensic cleanup functionality capable of removing persistence artifacts and deleting files and directories.
WaterPlum distributes OtterCandy through fraudulent technical-interview and recruitment workflows aimed particularly at software developers, job seekers, and blockchain, cryptocurrency, and Web3 personnel. ClickFake Interview operations use fake employer sites and ClickFix-style execution flows, including malicious software presented as interview-related camera setup or driver-update material. OtterCandy activity has been observed against victims in Japan and other regions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“OtterCandy — A related malware family incorporating capabilities associated with OtterCookie and RATatouille.”
12 distinct techniques documented for this family, organized by ATT&CK tactic.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Related WaterPlum malware family combining capabilities associated with OtterCookie and RATatouille.
A malware strain identified on victim devices in WaterPlum's job-seeker targeting campaign, which steals cryptocurrency wallet credentials and other information.
Post ... "Hands-on-Keyboard Activity from the DPRK \"PolinRider\" Supply Chain Attack" ... #PyPI, #OtterCandy, #PolinRider
A named malware family/tool referenced as being used by WaterPlum.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.