logo

New North Korean campaign uses fake coding interviews to steal developer credentials

ID: a5a6f689-482c-5ad3-a82f-3a6b079d0132

STIX ID: report--a5a6f689-482c-5ad3-a82f-3a6b079d0132

Feed Name: Elastic Security Labs

Threat Score
88/100

Date Published: 2026-07-18

Date Updated: 2026-07-17

...
...

Elastic Security Labs discovered a DPRK-linked campaign (REF9403 / Contagious Interview) that distributes trojanized developer coding challenges containing JavaScript malware hidden via Base64 steganography in SVG flag images; the multi-stage payload (OTTERCOOKIE-like) steals browser credentials and crypto wallets, exfiltrates files, establishes a Socket.IO RAT to controller.rightwidth.dev, and includes clipboard-stealing and Windows dropper capabilities, with multiple repository hashes, C2 domains, and IPs provided as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.