DEV Community

Mark0
Mark0

Posted on

New North Korean campaign uses fake coding interviews to steal developer credentials

Elastic Security Labs has identified a new DPRK-aligned campaign dubbed REF9403, which targets developers through fraudulent job offers and coding challenges. The attack utilizes steganography within SVG image files to deliver a multi-stage payload, including the OTTERCOOKIE infostealer and a Socket.IO-based remote access trojan (RAT).

The infection chain is triggered when a developer executes a trojanized repository, which contains seemingly benign code that silently reassembles malicious fragments hidden in image comments. Once active, the malware exfiltrates browser credentials, cryptocurrency wallets, and sensitive files, highlighting the significant risks of supply chain attacks originating from individual developer compromises.


Read Full Article

Top comments (0)