WaterPlumが使用するマルウェアOtterCandyについて
2025-10-15 • NTTSecurity • About OtterCandy malware used by WaterPlum •
https://jp.security.ntt/insights_resources/tech_blog/ottercandy_malware_j/
NTT analyzed OtterCandy, a Node.js RAT and information stealer used by WaterPlum Cluster B, also described as the BlockNovas cluster, in ClickFake Interview activity linked in the source to North Korea. The cluster previously used shared WaterPlum tooling such as BeaverTail, GolangGhost, and FrostyFerret, but began distributing OtterCandy across Windows, macOS, and Linux around July 2025. OtterCandy connects to C2 over Socket.IO, accepts remote commands, and is used to steal browser credentials, cryptocurrency wallets, and sensitive files from victim machines. The August 2025 v2 update added client_id-based victim tracking, expanded browser-extension and Chromium data theft, and cleanup logic for persistence artifacts, with listed infrastructure including 162[.]254.35.14, 74[.]119.194.205, 172[.]86.114.31, 139[.]60.163.206, 212[.]85.29.133, and 80[.]209.243.85.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 80.209.243.85 | 2025-10-15 | 2025-10-15 |
| IPv4 | 139.60.163.206 | 2025-10-15 | 2025-10-15 |
| IPv4 | 172.86.114.31 | 2025-10-15 | 2025-10-15 |
| IPv4 | 162.254.35.14 | 2025-10-15 | 2025-10-15 |
| IPv4 | 74.119.194.205 | 2025-10-15 | 2025-10-15 |
| IPv4 | 212.85.29.133 | 2025-10-15 | 2025-10-15 |