CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

New North Korean campaign uses fake coding interviews to steal developer credentials

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2774

As cited

Copy frozen at (site build).

threat intel

New North Korean campaign uses fake coding interviews to steal developer credentials

Elastic Security Labs discovered a North Korean-aligned campaign, tracked as REF9403, that uses fake job postings and coding challenges to distribute malware hidden in SVG image files via steganography. The trojanized code repositories appear functional but install a four-stage payload including credential and wallet stealers, file exfiltration, a Socket.IO-based remote access trojan, and clipboard stealing capabilities. The campaign demonstrates how threat actors target developers to establish initial access for downstream supply chain attacks.

Why it matters: Developers are at direct risk from social engineering in forums and job boards; compromising a single developer can provide attackers entry into their employer's systems and supply chain, making this a critical threat for security teams managing developer access and code review processes.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

New North Korean campaign uses fake coding interviews to steal developer credentials

Elastic Security Labs discovered a North Korean-aligned campaign, tracked as REF9403, that uses fake job postings and coding challenges to distribute malware hidden in SVG image files via steganography. The trojanized code repositories appear functional but install a four-stage payload including credential and wallet stealers, file exfiltration, a Socket.IO-based remote access trojan, and clipboard stealing capabilities. The campaign demonstrates how threat actors target developers to establish initial access for downstream supply chain attacks.

Why it matters: Developers are at direct risk from social engineering in forums and job boards; compromising a single developer can provide attackers entry into their employer's systems and supply chain, making this a critical threat for security teams managing developer access and code review processes.

VendorsGoogleAdobeSlack
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary