North Korea-Linked Contagious Interview Actors (REF9403) Hide OtterCookie-Aligned Malware in SVG Flag Images — Threadlinqs Intelligence
As of 2026-07-17, North Korea-Linked Contagious Interview Actors (REF9403) Hide OtterCookie-Aligned Malware in SVG Flag Images is a high-severity malware threat attributed to REF9403 (North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-1452 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: REF9403 · North Korea · FINANCIAL
North Korean threat actors tracked as REF9403, part of the Contagious Interview / DeceptiveDevelopment campaign, distribute fake coding-test job assignments via Slack #jobs channels containing
REF9403 is a North Korea-aligned cluster operating within the broader Contagious Interview (also tracked as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, TAG-121, CL-STA-0240, MITRE ATT&CK Group G1052) supply-chain social-engineering campaign, active since at least November 2023 and assessed by ESET (November 2024) to overlap with Lazarus Group cryptocurrency-theft operations. In this iteration, operators posted recruitment lures — using the persona "Maxwell" observed in late May 2026 in the Elastic Security community Slack workspace — advertising e-commerce platform upgrade contract work requiring Next.js, NestJS, PostgreSQL, Auth.js, and Stripe integration skills. Victims expressing interest are directed to a trojanized GitHub/GitLab/Bitbucket repository that appears to be a legitimate coding assignment.
The novel tradecraft in this wave is steganographic payload concealment inside SVG country-flag image assets (e.g. AE.svg, AF.svg) shipped as normal-looking UI assets within the fake project. Base64-encoded JavaScript fragments are hidden inside HTML comments in these SVG files; a companion script, serverValidation.js, reassembles the fragments into a working payload at runtime. Because the surrounding project code executes normally, the technique is designed to survive casual code review, and the malware re-triggers on every server/dev-environment boot, giving durable execution without an explicit persistence artifact in most cases.
The reassembled payload aligns with OtterCookie, a JavaScript-based, cross-platform (Windows/Linux/macOS) infostealer-RAT that emerged in September 2024 and has been iteratively hardened by the operators (Microsoft documented a heavily obfuscated October 2025 variant using encoded index lookups and shuffled arrays to defeat static/signature analysis). The four observed payload stages are: (1) a browser-credential and cryptocurrency-wallet stealer targeting Chrome/Brave stores and wallet mnemonic/private-key artifacts; (2) a file stealer that specifically enumerates and exfiltrates AI coding-assistant configuration directories (.claude, .cursor, .gemini, .windsurf, .pearai, .llama) alongside classic credential stores (KeePass, 1Password, SSH/GPG keys, .env files); (3) a Socket.IO-based remote access trojan that registers the infected host with a C2 endpoint, performs VM/sandbox detection, fingerprints the host (hostname, network identifiers, OS, public IP), and executes arbitrary shell commands tasked by the operator; and (4) a clipboard-monitoring/screenshot module (leveraging benign-looking auxiliary npm packages such as node-global-key-listener and screenshot-desktop) for ambient surveillance and credential capture.
The campaign's infrastructure model chains GitHub-hosted trojanized repos to Vercel-hosted staging pages (previously observed: tetrismic.vercel.app) for payload delivery, with URL-shortening services (short.gy) used to obscure links, before handing off to attacker C2 for tasking and exfiltration via axios-based multipart form-data uploads. Related npm-based waves of the same operator infrastructure (Socket, reported concurrently) added 197 new malicious/typosquatted packages (e.g. tailwind-magic, node-tailwind, node-tailwind-magic, react-modal-select) impersonating tailwind-merge and accumulating over 31,000 downloads, published from the GitHub account stardev0914 (18 repositories) — illustrating the same actor set's parallel supply-chain-poisoning line of effort alongside the direct-interview-lure vector used against this specific target set.
The explicit targeting of AI coding-tool configuration directories is a novel objective for this cluster: harvesting .claude/.cursor/.gemini/.windsurf/.pearai/.llama config and credential material gives the operators access to API keys, MCP/tool tokens, and workspace context that can be pivoted into further supply-chain compromise of downstream projects the victim works on — consistent with REF9403's overa
Weaknesses (CWE)
CWE-506, CWE-912, CWE-829
Target sectors: technology, cryptocurrency, web3, software-development, fintech
Target regions: Global, North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1589, T1593, T1593, T1583, T1583, T1583, T1585, T1587, T1588, T1588