#OtterCandy
Malware/Tool
2025-10-15 • OtterCandy, malware used by WaterPlum
OtterCandy is a Node.js remote access trojan and information stealer used by WaterPlum Cluster B, also called BlockNovas, in ClickFake Interview activity. From around July 2025 it was distributed against Windows, macOS, and Linux systems. It connects to its command-and-control server with Socket.IO, accepts operator commands, and steals browser credentials, cryptocurrency wallets, and sensitive files. DiggingBeaver establishes persistence, while OtterCandy can refork itself after receiving SIGINT. A late-August update added a client identifier to improve victim tracking.
-
2
Tagged Reports
-
1
Unique Authors
-
1
Active Days