North Korean Contagious Interview Campaign Hides Malware in Fake Coding Tests
ID: 0c8c34ba-9333-553a-89a9-e0f20d3682e7
STIX ID: report--0c8c34ba-9333-553a-89a9-e0f20d3682e7
Feed Name: securityonline.info
Elastic Security Labs uncovered a DPRK-linked campaign dubbed Contagious Interview that social-engineers developers with fake recruiter job lures and trojanized coding-project repositories; the attackers hide Base64-encoded payload fragments inside SVG flag images which a helper script reconstructs at runtime to deploy a four-part infostealer/backdoor and clipboard stealer across Windows, macOS, and Linux, enabling credential and crypto wallet theft and supply-chain propagation via pushed GitHub repos.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
