THREATOPS
THREAT OPSThreat News › New North Korean campaign uses fake coding interviews to steal developer credentials

New North Korean campaign uses fake coding interviews to steal developer credentials

medelastic_securityPublished 2026-07-18

<p>Elastic Security Labs found a new <a href="https://attack.mitre.org/groups/G1052/">Contagious Interview</a> campaign, tracked as REF9403, hiding malware inside SVG image files using steganography. To our knowledge, this specific infection chain has not been previously documented. We found it after the DPRK-aligned group targeted our own community Slack workspace with a fake job posting and a &q

Attributed threat actors

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography