Skip to content

North Korean APT Hides OtterCookie Malware in SVG Files from Fake Coding Tests

Bottom line: North Korean APT conceals four-stage OtterCookie malware via steganography in SVG files embedded in fraudulent coding challenges.

North Korean actors from the “Contagious Interview” campaign use steganography in SVG image files to hide four-stage malware payloads. These are distributed through fake job postings and programming tasks.

The attackers hide malicious payloads in SVG files (Scalable Vector Graphics) that appear as normal graphics. Users who completed the affected coding challenges received a four-stage malware chain customized for OtterCookie.

OtterCookie functions as a credential and crypto-wallet stealer as well as a file stealer, specifically targeting login credentials and digital assets stored in browsers. The campaign leverages social engineering through realistic job postings and technical tests to lure developers and IT professionals.

For CISOs, this is an indicator of growing sophistication in supply-chain and recruitment-based attacks. Steganography in SVG files complicates detection by common security tools, since the malware is not packaged in classic executable formats. Organizations should prioritize sandbox testing and behavioral analysis for suspicious code downloads and raise awareness among HR and recruiting teams.


Source: thehackernews.com · Published 17 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.

Share on: