www.elastic.co
North Korean Hackers Use SVG Steganography in Job Scam Malware Campaign
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
DPRK-aligned hackers have launched a campaign known as Contagious Interview, utilizing steganography to hide malware within SVG flag images. This malware targets developers through fake job postings and coding challenges, delivering a four-stage payload that includes a credential stealer, file stealer, remote access trojan, and clipboard stealer. The campaign was first identified when suspicious activity was detected in a community Slack workspace, where a user solicited developers for a project. The malware is delivered through trojanized repositories that have not been flagged by antivirus vendors. The attack emphasizes the vulnerability of developers, as compromising a single individual can lead to extensive supply chain attacks. Multiple campaigns with similar tactics have been identified, indicating a broader threat landscape. As of now, the malware remains undetected by major antivirus solutions.
Key Points: • DPRK hackers exploit developer job offers to distribute malware via SVG images. • The malware payload includes credential stealers and a remote access trojan. • Multiple campaigns using similar tactics have been identified, targeting open developer forums.