North Korea hides OtterCookie malware inside SVG flag images in fake coding tests

North Korean threat actors embed malware payload fragments inside SVG country flag images distributed through fake developer job interviews and coding challenges.

CSBadmin
1 Min Read

North Korean threat actors linked to the ongoing Contagious Interview campaign have been using steganography in SVG image files to conceal malicious payloads, according to Elastic Security Labs. The campaign targets software developers through fake job postings on Slack and coding challenges on GitHub.

The attackers, tracked as REF9403, approached developers on the Elastic community Slack workspace in late May 2026 with a fraudulent job offer requiring completion of a Next.js coding assessment. The trojanized repository includes fully functional code with malicious payloads hidden inside SVG country flag images. Base64 fragments are split across HTML comments inside every SVG file in the assets directory.

A JavaScript file called serverValidation.js assembles the fragments into a four-stage payload aligned with OtterCookie: a browser credential and crypto wallet stealer, a file stealer, a Socket.IO-based RAT, and a clipboard stealer. The malware triggers silently on each server boot.

OtterCookie has evolved significantly since September 2024, adding VM detection, modular data theft, and arbitrary shell command execution capabilities. Elastic confirmed seeing victims actually run the challenge before realizing the job recruiter had disappeared, suggesting the campaign remains effective through its persistent social engineering approach.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.