216.73.216.197

Contagious Interview malware in SVG images: DPRK campaign

· Published 17/07/2026 22:08

Export JSON

Essential information

Published
17/07/2026 22:08
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
beavertail cryptocurrency wallet theft developer targeting dprk fake job interviews ottercookie steganography supply chain attack svg
Related entities
13 indicators, 4 observables, 1 intrusion sets (apt), 19 techniques (mitre), 2 malware

Description

A -aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using inside flag images. When developers run these projects, the malware deploys four-stage payloads aligned with : a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this vector against software developers.

External references