Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
ID: 4df67672-5826-5f9c-ad48-1b958195a2b8
STIX ID: report--4df67672-5826-5f9c-ad48-1b958195a2b8
Feed Name: The Hacker News
North Korean-linked threat actors (REF9403/Contagious Interview) targeted software developers via fake job postings and trojanized coding assessments that hide Base64-encoded payload fragments inside SVG image comments. A JavaScript loader reassembles the fragments into a four-stage OtterCookie-derived malware (browser and crypto wallet stealer, file stealer, Socket.IO-based RAT, clipboard stealer), enabling data exfiltration, persistent remote access, and supply-chain risk to downstream organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
