North Korean Hackers Hide Malware in SVG Job Postings
State-backed attackers are embedding malicious code in fake coding tests using SVG steganography. The campaign targets developers with job offers to deploy multi-stage stealers.
TL;DR
- Contagious Interview campaign uses fake job posts to target devs
- Malware hidden in SVG flag images via steganography techniques
- Four-stage OTTERCOOKIE payload steals browser creds and crypto wallets
- File stealer component exfiltrates sensitive local data
- Campaign linked to North Korean state-sponsored threat actors
Security researchers have uncovered a sophisticated campaign leveraging fake job opportunities to deliver malware to unsuspecting developers. The Contagious Interview operation, attributed to North Korean threat actors, employs advanced steganography techniques to hide malicious payloads within seemingly innocent SVG image files.
The attack begins when victims encounter fake coding challenges that appear legitimate, often disguised as employment screening tools. Once executed, these projects deploy a complex four-stage malware toolkit designed to compromise sensitive information including browser credentials and cryptocurrency wallets.
Attack Vector and Delivery Method
- Threat actors create fake job postings requiring coding test submissions
- SVG image files contain embedded malicious payloads using steganography
- Victims unknowingly execute multi-stage malware when running test projects
- Initial access achieved through social engineering targeting developers specifically
Malware Capabilities and Impact
- OTTERCOOKIE malware includes browser credential and crypto wallet stealing components
- File stealer module extracts sensitive documents and data from compromised systems
- Four distinct stages make detection and analysis more challenging
- Campaign demonstrates evolving sophistication in state-sponsored developer targeting
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.