North Korean Hackers Use SVG Steganography in Job Scam Malware Campaign
ID: 1f19e454-77ec-5b5e-979c-686bcbfe3e5b
STIX ID: report--1f19e454-77ec-5b5e-979c-686bcbfe3e5b
Feed Name: ThreatCluster
Threat Score
**Executive Summary:** DPRK-aligned operators are running the "Contagious Interview" campaign that lures developers with fake job offers and coding challenges, hiding a multi-stage malware payload inside SVG flag images via steganography; the attack delivers credential and file stealers, a remote access trojan, and a clipboard stealer through trojanized repositories, evades major antivirus detection, and creates significant supply-chain risks to developer ecosystems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
