North Korean Hackers Use Steganography in Fake Coding Tests to Deliver OtterCookie Malware

North Korean threat actors linked to the Contagious Interview campaign have been observed using steganography techniques in SVG image files to conceal multi-stage malware payloads. The campaign leverages fake job postings and coding challenges to trick users into executing the malware, which includes components to steal browser credentials, cryptocurrency wallets, and files.
What happened
Researchers have identified a sophisticated malware distribution tactic employed by North Korean-linked hacking groups known as the Contagious Interview campaign. Attackers use fake job postings and coding challenge projects embedded with SVG images that hide malicious payloads through steganography. When a user runs the project, it deploys a four-stage infection chain associated with OtterCookie malware.
The executed malware includes a browser credential and cryptocurrency wallet stealer as well as a file stealer, enabling attackers to harvest sensitive information from compromised systems. The use of steganography in SVG files to deliver the payloads represents an advanced obfuscation method designed to evade detection during the initial infection vector.
Why it matters
This campaign highlights the increasing sophistication of North Korean threat actors in evading security defenses by embedding malware within seemingly benign images distributed through social engineering tactics like fake job recruitment. The multi-stage OtterCookie-aligned malware poses significant risks due to its data theft capabilities targeting credentials and cryptocurrency wallets.
Organizations and users engaging with unsolicited coding tests or suspicious job offers should exercise caution, as these types of social engineering schemes continue to evolve with advanced delivery methods. The alignment of this malware with known North Korean tools underscores persistent geopolitical-motivated cyber threats.
What security teams should do
Security teams should be vigilant about monitoring for suspicious coding challenges and job recruitment schemes delivered via email or social platforms. Conducting thorough analysis of SVG files and other image types incorporated in code projects can help detect steganographic payloads.
Incident response teams should validate systems for signs of credential theft and unauthorized data exfiltration, particularly regarding browser credentials and cryptocurrency wallets. Organizations are advised to educate users about the risks of running untrusted code from unfamiliar sources, especially in recruitment scenarios involving coding tests.
Key technical details
The attackers utilize steganography within SVG image files to conceal a four-stage payload associated with OtterCookie malware. Once the project containing the malicious SVG is run, the infection chain initiates components responsible for stealing browser credentials, cryptocurrency wallet data, and files from the victim's system.
This approach leverages complex file-hiding techniques to bypass traditional detection mechanisms and exploit user trust established through fake job postings and coding challenges. The multi-stage payload indicates a well-developed attack sequence designed for comprehensive data theft.
Affected organizations/products
The campaign targets individuals who engage with fake coding tests and job postings, potentially affecting developers and job seekers who run the distributed projects containing the malicious SVG images.
Source attribution
https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html