Elastic Security Labs has identified a new campaign from the DPRK-aligned group known as Contagious Interview, tracked as REF9403. The threat actors target developers through fake job postings and coding challenges on platforms like Slack. The attack utilizes a sophisticated infection chain that hides malicious code inside SVG images using steganography, which is then reassembled and executed when the victim runs the provided project. This technique allows the group to bypass traditional security detections while appearing as a benign Next.js or e-commerce template.
The resulting infection deploys a multi-stage payload aligned with the OTTERCOOKIE malware family. This malware includes a browser credential and cryptocurrency wallet stealer, a file exfiltrator targeting sensitive developer data like SSH keys and AWS configurations, a Socket.IO-based remote access trojan (RAT), and a clipboard stealer. By compromising individual developer environments, the threat actors aim to secure initial access for high-impact supply chain attacks against downstream organizations.
Top comments (0)