WaterPlumが使用するマルウェアOtterCandyについて

2025-10-15 NTTSecurity About OtterCandy malware used by WaterPlum

https://jp.security.ntt/insights_resources/tech_blog/ottercandy_malware_j/

Thumbnail for WaterPlumが使用するマルウェアOtterCandyについて

NTT analyzed OtterCandy, a Node.js RAT and information stealer used by WaterPlum Cluster B, also described as the BlockNovas cluster, in ClickFake Interview activity linked in the source to North Korea. The cluster previously used shared WaterPlum tooling such as BeaverTail, GolangGhost, and FrostyFerret, but began distributing OtterCandy across Windows, macOS, and Linux around July 2025. OtterCandy connects to C2 over Socket.IO, accepts remote commands, and is used to steal browser credentials, cryptocurrency wallets, and sensitive files from victim machines. The August 2025 v2 update added client_id-based victim tracking, expanded browser-extension and Chromium data theft, and cleanup logic for persistence artifacts, with listed infrastructure including 162[.]254.35.14, 74[.]119.194.205, 172[.]86.114.31, 139[.]60.163.206, 212[.]85.29.133, and 80[.]209.243.85.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 80.209.243.85 2025-10-15 2025-10-15
IPv4 139.60.163.206 2025-10-15 2025-10-15
IPv4 172.86.114.31 2025-10-15 2025-10-15
IPv4 162.254.35.14 2025-10-15 2025-10-15
IPv4 74.119.194.205 2025-10-15 2025-10-15
IPv4 212.85.29.133 2025-10-15 2025-10-15

Related Actors

Related Reports

« Back