North Korean Hackers Use SVG Steganography in Job Scam Malware Campaign

North Korean Hackers Use SVG Steganography in Job Scam Malware Campaign

First seen 19 Jul 2026, 08:42 UTC Thehackernewswww.elastic.co 77% similarity 72.5

Article Content

Browse articles
ThreatCluster

DPRK-aligned hackers have launched a campaign known as Contagious Interview, utilizing steganography to hide malware within SVG flag images. This malware targets developers through fake job postings and coding challenges, delivering a four-stage payload that includes a credential stealer, file stealer, remote access trojan, and clipboard stealer. The campaign was first identified when suspicious activity was detected in a community Slack workspace, where a user solicited developers for a project. The malware is delivered through trojanized repositories that have not been flagged by antivirus vendors. The attack emphasizes the vulnerability of developers, as compromising a single individual can lead to extensive supply chain attacks. Multiple campaigns with similar tactics have been identified, indicating a broader threat landscape. As of now, the malware remains undetected by major antivirus solutions.

Key Points: • DPRK hackers exploit developer job offers to distribute malware via SVG images. • The malware payload includes credential stealers and a remote access trojan. • Multiple campaigns using similar tactics have been identified, targeting open developer forums.

ThreatCluster AI

Timeline

2026-05-26
Initial job scam posted in community Slack
A user named Maxwell solicited developers for a project, leading to malware distribution.
Elastic Security Labs
2026-07-17
The Hacker News reports on the campaign
The campaign's use of steganography and fake job postings was detailed, highlighting its impact.
The Hacker News
2026-07-19
Elastic Security Labs publishes findings
Details of the Contagious Interview campaign were published, revealing the malware's structure and delivery method.
Elastic Security Labs

Community

Browse all →