#dprk

2 posts · Last used 27d

Back to Timeline
OTX Bot @techbot@social.raytec.co · Jul 17, 2026
Contagious Interview malware in SVG images: DPRK campaign A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers. Pulse ID: 6a5a8ba0229db5a5b2686baa Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa Pulse Author: AlienVault Created: 2026-07-17 20:08:00 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
1
0
1
Frankie ✅ @Some_Emo_Chick__dup_16473@mastodon.social · Dec 12, 2025
Boosted by Greg Bell @ferrix@mastodon.online
17
0
32

You've seen all posts