New North Korean Campaign Uses Fake Coding Interviews to Steal Developer Credentials

    Date: 07/20/2026

    Severity: High

    Summary

    Security Labs identified a new Contagious Interview campaign, tracked as REF9403, that hides malware inside SVG image files using steganography. The infection chain appears to be previously undocumented. The campaign was uncovered after a DPRK-linked threat actor targeted the team's Slack workspace with a fake job posting and a malicious coding challenge. Users who executed the project were infected through a four-stage attack chain delivering OTTERCOOKIE and multiple payloads, including a browser credential and crypto wallet stealer, a file stealer, a Socket.IO-based RAT, and a clipboard stealer. The campaign demonstrates how threat actors continue to target software developers through fake recruitment scams. Compromising a single developer can provide attackers with an entry point for broader supply chain attacks against downstream organizations. 

    Indicators of Compromise (IOC) List  

    Domains/URLs

    rightwidth.dev

    ldb.rightwidth.dev

    upload.rightwidth.dev

    controller.rightwidth.dev

    file.rightwidth.dev

    IP Address 

    195.26.248.212

    188.40.64.61

    Hash 

    8e571d58794b9b44ae53c2c67bedef72c500e8adbb80aab7a5c263adcba55b1e

    3e6360f83a95540aa2176d279ca4694513afb1e5116a7ffe591c6b5bcf3b9c3c

    4e7639045b4a64de60bfb6312951a5c3dffbd3fb04b84837663242ed27f09864

    54bf36910d81ab516037cb3d69d7c85190f90aa0da9e58617799c1fc738dc5a9

    96357529d17c4690826d5d4c74deac51743a5388733b3f04004d898f0635ef20

    9df01d242ef46adfedf8c35cb7cc67b1d27d7dc4a1ce74ab32e984090d579886

    c5aed4c063d4970a03250778da8041da9e0c83d8f22d2f1994da0ad72567ebd9

    cc97517f80f567977300450de11e9a0be53f52657525a20b1091c99fe9e45730

    fb94b2caee2c40635448a98ba0118421e19a400e74ccff73315f8fa42351f53f

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection 

    Detection Query 1 :

    domainname like "rightwidth.dev" or url like "rightwidth.dev" or siteurl like "rightwidth.dev" or domainname like "controller.rightwidth.dev" or url like "controller.rightwidth.dev" or siteurl like "controller.rightwidth.dev" or domainname like "file.rightwidth.dev" or url like "file.rightwidth.dev" or siteurl like "file.rightwidth.dev" or domainname like "ldb.rightwidth.dev" or url like "ldb.rightwidth.dev" or siteurl like "ldb.rightwidth.dev" or domainname like "upload.rightwidth.dev" or url like "upload.rightwidth.dev" or siteurl like "upload.rightwidth.dev"

    Detection Query 2 :

    dstipaddress IN ("188.40.64.61","195.26.248.212") or srcipaddress IN ("188.40.64.61","195.26.248.212")

    Detection Query 3 :

    sha256hash IN ("4e7639045b4a64de60bfb6312951a5c3dffbd3fb04b84837663242ed27f09864","cc97517f80f567977300450de11e9a0be53f52657525a20b1091c99fe9e45730","54bf36910d81ab516037cb3d69d7c85190f90aa0da9e58617799c1fc738dc5a9","c5aed4c063d4970a03250778da8041da9e0c83d8f22d2f1994da0ad72567ebd9","96357529d17c4690826d5d4c74deac51743a5388733b3f04004d898f0635ef20","3e6360f83a95540aa2176d279ca4694513afb1e5116a7ffe591c6b5bcf3b9c3c","8e571d58794b9b44ae53c2c67bedef72c500e8adbb80aab7a5c263adcba55b1e")

    Reference:    

    https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography                     


    Tags

    MalwareThreat ActorNorth KoreaCredential HarvestingSteganographyDPRKInformation TechnologyOtterCookieRATStealerSupply chain attack

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags