OpenCandy is an adware module and potentially unwanted program produced by SweetLabs that was bundled into Microsoft Windows software installers to present additional software offers during installation. Many antivirus vendors classified it as malware or unwanted software. It operated as a Windows library incorporated into Windows Installer packages and, when a bundled application was installed, displayed recommendations for additional software based on a scan of the user’s system and geolocation. The offers were preselected by default unless manually unchecked. Reported side effects included changing the user’s homepage, desktop background, or search provider, and installing unwanted toolbars, plug-ins, and browser extension add-ons. The content also states that OpenCandy collected and transmitted user and web-usage information without notification or consent. Known related files included OCComSDK.dll, OCSetupHlp.dll, and Fusion.dll, and related processes included spidentifier.exe and rundll32.exe. Referenced infrastructure included tracking.opencandy.com.s3.amazonaws.com, media.opencandy.com, cdn.opencandy.com, cdn.putono5.com, tracking.opencandy.com, api.opencandy.com, and www.arcadefrontier.com. OpenCandy was embedded in installers for numerous applications including AC3Filter, Auslogics Disk Defrag, CamStudio, CDBurnerXP, FileZilla, Format Factory, Foxit Reader, FreeFileSync, FrostWire, GOM Player, ImgBurn, mIRC, MP3 Rocket, Orbit Downloader, PDFCreator, PhotoScape, PrimoPDF, Sigil, Trillian, uTorrent, WinSCP, and the FL Studio installer. Specific examples mentioned include Foxit Reader 6.1.4 through 6.2.1, ImgBurn starting with 2.5.8.0 in the installer from imgburn.com, and WinSCP through August 2012. Some installers supported a /NOCANDY command-line parameter to bypass it. Windows Defender detected an FL Studio 12.1.2 installer component associated with OCSetupHlp.dll as PUA:Win32/CandyOpen. Following substantial criticism, OpenCandy was discontinued in August 2016.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An adware module bundled with software installers on Windows that presented preselected software offers during installation, could change browser and desktop settings, add toolbars or extensions, and collect and transmit user and web-usage information without clear consent. It was discontinued in August 2016.
2008 Agent.BTZ Asprox Conficker Fun.exe Hupigon Mariposa MonaRonaDona OpenCandy
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.