hacker-news · Crawled Jul 17, 2026
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
2 IoCs 1 Malware
Read original article ↗
AI Summary
North Korean threat actors linked to the Contagious Interview campaign are targeting software developers through fake job postings and coding challenges. They distribute malicious repositories that include SVG images with steganographically hidden payloads, which deploy the OtterCookie malware. This multi-stage malware steals browser credentials, cryptocurrency wallets, files, and clipboard data, while also enabling remote access via a Socket.IO-based backdoor.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 2 extracted
MITRE ATT&CK TTPs 19 techniques
T1003 OS Credential Dumping · Credential Access T1005 Data from Local System · Collection T1027 Obfuscated Files or Information · Defense Evasion T1056.001 Keylogging · Collection T1056.002 GUI Input Capture · Collection T1059.001 PowerShell · Execution T1059.007 JavaScript · Execution T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1110 Brute Force · Credential Access T1113 Screen Capture · Collection T1114 Email Collection · Collection T1123 Audio Capture · Collection T1195.002 Compromise Software Supply Chain · Initial Access T1555 Credentials from Password Stores · Credential Access T1566 Phishing · Initial Access