North Korean Hackers Use Fake Coding Tests With Malware Hidden in SVG Image Files

North Korean threat actors have been caught using steganography techniques to conceal malicious payloads inside SVG image files as part of a campaign using fake job postings and coding challenges. The operation targets developers with false employment opportunities to trick them into running malware on their systems.

The campaign, tracked as Contagious Interview, involves threat actors approaching software developers on professional networking platforms with enticing job offers. The recruitment process includes coding challenges that, when completed, deploy a four-stage malware payload called OtterCookie that steals browser credentials, crypto wallet data, and sensitive files.

The use of SVG files for steganography is particularly notable because SVG is an image format that can contain embedded XML data, making it straightforward to hide malicious code alongside legitimate image content. Security tools that scan for traditional binary file formats may overlook these embedded threats.

The OtterCookie malware is designed to siphon a wide range of sensitive information from compromised systems, focusing on cryptocurrency wallets and browser-stored credentials. The stolen data is exfiltrated to attacker-controlled servers, where it can be used for financial theft or further intrusion into connected systems.

This campaign represents an ongoing evolution in North Korean cyber operations, which have increasingly targeted the cryptocurrency and blockchain sectors. Developers working with cryptocurrency technologies are urged to verify the legitimacy of unsolicited job offers and avoid running code from untrusted sources.

This article was adapted from The Hacker News. Read the original here.