THREAT OPS › Threat News › New North Korean campaign uses fake coding interviews to steal developer credentials
New North Korean campaign uses fake coding interviews to steal developer credentials
<p>Elastic Security Labs found a new <a href="https://attack.mitre.org/groups/G1052/">Contagious Interview</a> campaign, tracked as REF9403, hiding malware inside SVG image files using steganography. To our knowledge, this specific infection chain has not been previously documented. We found it after the DPRK-aligned group targeted our own community Slack workspace with a fake job posting and a &q
Attributed threat actors
- Contagious InterviewG1052
MITRE ATT&CK techniques
- JavaScriptT1059.007
- Browser ExtensionsT1176.001
- Clipboard DataT1115
- System Information DiscoveryT1082
- Application Layer ProtocolT1071
- Data from Local SystemT1005
- Credentials from Password StoresT1555
- MasqueradingT1036
- File and Directory DiscoveryT1083
- Exfiltration Over C2 ChannelT1041
- PowerShellT1059.001
- Data ObfuscationT1001
- CredentialsT1589.001
- SteganographyT1027.003
- Web ProtocolsT1071.001
- Ingress Tool TransferT1105
- SteganographyT1001.002
- Data from Local SystemAML.T0037
- MasqueradingAML.T0074
Indicators of compromise
- 8e571d58794b9b44ae53c2c67bedef72c500e8adbb80aab7a5c263adcba55b1esha256
- 3e6360f83a95540aa2176d279ca4694513afb1e5116a7ffe591c6b5bcf3b9c3csha256
- 4e7639045b4a64de60bfb6312951a5c3dffbd3fb04b84837663242ed27f09864sha256
- 54bf36910d81ab516037cb3d69d7c85190f90aa0da9e58617799c1fc738dc5a9sha256
- 96357529d17c4690826d5d4c74deac51743a5388733b3f04004d898f0635ef20sha256
- 9df01d242ef46adfedf8c35cb7cc67b1d27d7dc4a1ce74ab32e984090d579886sha256
- c5aed4c063d4970a03250778da8041da9e0c83d8f22d2f1994da0ad72567ebd9sha256
- cc97517f80f567977300450de11e9a0be53f52657525a20b1091c99fe9e45730sha256
- fb94b2caee2c40635448a98ba0118421e19a400e74ccff73315f8fa42351f53fsha256
- https://nextjs.org/url
- https://jp.security.ntt/insights_resources/tech_blog/en-contagious-interview-ottercookie/url
- https://research.jfrog.com/post/rollup-polyfill-masquerading/url
- https://obfuscator.io/url
- https://socket.io/url
- 195.26.248.212ipv4
- 188.40.64.61ipv4
- crypto.comdomain