New North Korean campaign uses fake coding interviews to steal developer credentials
ID: a5a6f689-482c-5ad3-a82f-3a6b079d0132
STIX ID: report--a5a6f689-482c-5ad3-a82f-3a6b079d0132
Feed Name: Elastic Security Labs
Elastic Security Labs discovered a DPRK-linked campaign (REF9403 / Contagious Interview) that distributes trojanized developer coding challenges containing JavaScript malware hidden via Base64 steganography in SVG flag images; the multi-stage payload (OTTERCOOKIE-like) steals browser credentials and crypto wallets, exfiltrates files, establishes a Socket.IO RAT to controller.rightwidth.dev, and includes clipboard-stealing and Windows dropper capabilities, with multiple repository hashes, C2 domains, and IPs provided as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
