North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images
ID: 3b054480-d15f-531d-a260-2f9b69f883bf
STIX ID: report--3b054480-d15f-531d-a260-2f9b69f883bf
Feed Name: GBHackers
A DPRK-linked campaign named “Contagious Interview” has evolved to use obfuscated JavaScript embedded in SVG images to deliver the OTTERCOOKIE modular backdoor and simultaneously carried out a RubyGems supply chain intrusion (git_credential_manager 2.8.0–2.8.3, Dendreo 1.1.3–1.1.4, fastlane-plugin-run_tests_firebase_testlab 0.3.2). The malicious gems act as loaders that fetch a shell script and a native daemon from attacker infrastructure (Forgejo git.disroot.org), install persistent agents under ~/.local/share/gcm/ and systemd/cron, perform credential harvesting and privilege escalation (including possible setuid root implant), and use environment checks to evade CI detection. Network telemetry and versioned package behavior indicate active, iterative testing and deployment, and researchers recommend treating systems that installed the packages as compromised, removing persistence artifacts, and rotating credentials while improving runtime monitoring and package provenance controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
