CTIPilot

OtterCandy

malware · malware:ottercandy

DPRK WaterPlum/Contagious Interview malware combining the features of OTTERCOOKIE and RATatouille (joint FBI/NPA-Japan/NCO-Japan/DC3/ASD-ACSC/BND/BfV Cybersecurity Advisory, 2026-09-18).

Coverage timeline
1
first 2026-09-19 → last 2026-09-19
Peak priority
high
1 high
Sources cited
4
4 hosts
Sections touched
1
active-threats
Co-occurring entities
7
see Co-occurring entities below
ATT&CK techniques
7
pinned v19.2 · see below

ATT&CK techniques

7 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-09-19/waterplum-contagious-interview-joint-advisory-scale · ATT&CK page ↗

Execution TA0002

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-09-19/waterplum-contagious-interview-joint-advisory-scale · ATT&CK page ↗

Credential Access TA0006

T1056.001Input Capture: Keylogging×1

Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.

Evidence: 2026-09-19/waterplum-contagious-interview-joint-advisory-scale · ATT&CK page ↗

T1555.003Credentials from Password Stores: Credentials from Web Browsers×1

Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.

Evidence: 2026-09-19/waterplum-contagious-interview-joint-advisory-scale · ATT&CK page ↗

Collection TA0009

T1056.001Input Capture: Keylogging×1

Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.

Evidence: 2026-09-19/waterplum-contagious-interview-joint-advisory-scale · ATT&CK page ↗

T1113Screen Capture×1

Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.

Evidence: 2026-09-19/waterplum-contagious-interview-joint-advisory-scale · ATT&CK page ↗

T1115Clipboard Data×1

Adversaries may collect data stored in the clipboard from users copying information within or between applications.

Evidence: 2026-09-19/waterplum-contagious-interview-joint-advisory-scale · ATT&CK page ↗

Command and Control TA0011

T1071Application Layer Protocol×1

Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-09-19/waterplum-contagious-interview-joint-advisory-scale · ATT&CK page ↗

Story timeline

  1. 2026-09-19WaterPlum ("Contagious Interview"): a seven-agency joint advisory quantifies the DPRK fake-job campaign for the first time, 30,000+ devices, 100+ countries, $10.7M in crypto, and Japan's first dismantled "laptop farm"
    active-threatsFBI, Japanese and German authorities jointly confirm DPRK's fake-interview crew has infected 30,000+ devices and drained $10.7M from crypto wallets

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

used by

Where this entity is cited

  • active-threats1

Source distribution

  • heise.de1 (25%)
  • ic3.gov1 (25%)
  • therecord.media1 (25%)
  • verfassungsschutz.de1 (25%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about OtterCandy (1)

2026-09-19 · view entry permalink →

HIGHNATOA1

WaterPlum ("Contagious Interview"): a seven-agency joint advisory quantifies the DPRK fake-job campaign for the first time, 30,000+ devices, 100+ countries, $10.7M in crypto, and Japan's first dismantled "laptop farm"

Seven government agencies (Japan's National Police Agency and National Cybersecurity Office, the US FBI and DoD Cyber Crime Center, Australia's Signals Directorate/ACSC, and Germany's BND and BfV) jointly published a Cybersecurity Advisory on 2026-09-18 on the North Korean "WaterPlum" cyber-actor group, publicly known as Contagious Interview and already tracked here under that name (FBI/IC3, 2026-09-18). The advisory is the first to attach concrete scale to the campaign: at least 30,000 infected devices across more than 100 countries, funds or credentials exfiltrated from over 7,000 cryptocurrency wallets, and roughly 1.7 billion Japanese yen (about USD 10.7 million) moved to DPRK (FBI/IC3, 2026-09-18). Germany's BfV confirms the campaign has targeted software developers "also in Germany" (translated from German) (Bundesamt für Verfassungsschutz, 2026-09-18).

WaterPlum poses as recruiters, frequently impersonating AI, cryptocurrency or NFT companies, and also using legitimate freelance and recruiting platforms, to lure software developers and IT professionals into a technical interview or take-home coding assignment; victims are told to download and run files hosted on collaboration platforms and code repositories to "complete a coding assignment or troubleshoot an error." Those files carry one of five malware families the advisory names for the first time together: BeaverTail (a JavaScript loader hidden in NPM packages hosted on GitHub or Bitbucket), InvisibleFerret (a Python backdoor), OtterCookie (a JavaScript RAT and infostealer, already tracked here from Elastic's 2026-07-18 SVG-steganography disclosure), OtterCandy (combining OtterCookie and RATatouille features), and StoatWaffle, a modular Node.js loader, credential harvester and RAT that hides inside blockchain-themed decoy VS Code project repositories and auto-executes through a malicious VS Code configuration file the moment the victim opens and trusts the folder (FBI/IC3, 2026-09-18). Once backdoored, operators use the RATs for persistence and lateral pivoting while infostealers harvest browser-stored credentials, clipboard contents, keystrokes, screenshots and cryptocurrency-wallet data to a command-and-control address; the same access lets operators pursue further espionage or intellectual-property theft inside the victim's employer.

The advisory ties the malware-delivery operation to North Korea's separate, long-running remote-IT-worker placement scheme (tracked here as PurpleDelta / Jasper Sleet / UNC5267 / Wagemole / Famous Chollima): "the NPA and the FBI assess both WaterPlum cyber actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea" (FBI/IC3, 2026-09-18); the two operations share a parent organization even though they run distinct tradecraft. Separately, Japanese authorities disclosed "for the first time in Japan" a dismantled "laptop farm" (a facility where an enabler physically hosted employer-issued laptops and remotely operated them on North Korean workers' behalf) moving "several hundred million" yen in cryptocurrency abroad (FBI/IC3, 2026-09-18). The advisory records two prior cases of IT-worker escalation beyond simple wage fraud: one worker extorted an employer over its own source code after a payment dispute, and another defaced and disabled a hiring company's website.

Triage: BeaverTail/InvisibleFerret/OtterCookie-family execution shows up as a node or python process spawned from an IDE or terminal session shortly after a new project folder is opened or an npm install completes, followed by outbound connections to non-corporate destinations and API calls against browser credential stores or the clipboard; legitimate build tooling does not read browser credential stores or poll the clipboard. StoatWaffle's variant of the same pattern is a VS Code auto-run entry (a .vscode configuration file) firing on folder-open/trust in a freshly cloned, blockchain-themed repository the organization's own ticketing has no record of. The distinguishing context, in both cases, is timing correlation with an active job-interview or coding-test process rather than the presence of node/npm/VS Code activity alone.

WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets. WaterPlum actors have transferred 1.7 billion Japanese yen (JPY) (equivalent to 10.71 million USD) of cryptocurrency assets to the Democratic People's Republic of Korea (DPRK).

WaterPlum actors upload malicious Node Package Manager (NPM) packages embedded with either BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle malware and related variants.

The NPA and the FBI assess both WaterPlum cyber actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea.

For the first time in Japan, authorities successfully identified, investigated, and dismantled a "laptop farm" operated by an enabler in Japan.

FBI/IC3 Joint Cybersecurity Advisory 2026-09-18

Builds on: 2026-09-08/sekoia-kudelski-dprk-lazarus-umbrella-six-cluster-split

threat19 Sep 04:40Zmulti-sourceOpen finding ↗