Date: 07/20/2026
Severity: High
Summary
Security Labs identified a new Contagious Interview campaign, tracked as REF9403, that hides malware inside SVG image files using steganography. The infection chain appears to be previously undocumented. The campaign was uncovered after a DPRK-linked threat actor targeted the team's Slack workspace with a fake job posting and a malicious coding challenge. Users who executed the project were infected through a four-stage attack chain delivering OTTERCOOKIE and multiple payloads, including a browser credential and crypto wallet stealer, a file stealer, a Socket.IO-based RAT, and a clipboard stealer. The campaign demonstrates how threat actors continue to target software developers through fake recruitment scams. Compromising a single developer can provide attackers with an entry point for broader supply chain attacks against downstream organizations.
Indicators of Compromise (IOC) List
Domains/URLs | rightwidth.dev ldb.rightwidth.dev upload.rightwidth.dev controller.rightwidth.dev file.rightwidth.dev |
IP Address | 195.26.248.212 188.40.64.61 |
Hash | 8e571d58794b9b44ae53c2c67bedef72c500e8adbb80aab7a5c263adcba55b1e
3e6360f83a95540aa2176d279ca4694513afb1e5116a7ffe591c6b5bcf3b9c3c
4e7639045b4a64de60bfb6312951a5c3dffbd3fb04b84837663242ed27f09864
54bf36910d81ab516037cb3d69d7c85190f90aa0da9e58617799c1fc738dc5a9
96357529d17c4690826d5d4c74deac51743a5388733b3f04004d898f0635ef20
9df01d242ef46adfedf8c35cb7cc67b1d27d7dc4a1ce74ab32e984090d579886
c5aed4c063d4970a03250778da8041da9e0c83d8f22d2f1994da0ad72567ebd9
cc97517f80f567977300450de11e9a0be53f52657525a20b1091c99fe9e45730
fb94b2caee2c40635448a98ba0118421e19a400e74ccff73315f8fa42351f53f
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "rightwidth.dev" or url like "rightwidth.dev" or siteurl like "rightwidth.dev" or domainname like "controller.rightwidth.dev" or url like "controller.rightwidth.dev" or siteurl like "controller.rightwidth.dev" or domainname like "file.rightwidth.dev" or url like "file.rightwidth.dev" or siteurl like "file.rightwidth.dev" or domainname like "ldb.rightwidth.dev" or url like "ldb.rightwidth.dev" or siteurl like "ldb.rightwidth.dev" or domainname like "upload.rightwidth.dev" or url like "upload.rightwidth.dev" or siteurl like "upload.rightwidth.dev" |
Detection Query 2 : | dstipaddress IN ("188.40.64.61","195.26.248.212") or srcipaddress IN ("188.40.64.61","195.26.248.212") |
Detection Query 3 : | sha256hash IN ("4e7639045b4a64de60bfb6312951a5c3dffbd3fb04b84837663242ed27f09864","cc97517f80f567977300450de11e9a0be53f52657525a20b1091c99fe9e45730","54bf36910d81ab516037cb3d69d7c85190f90aa0da9e58617799c1fc738dc5a9","c5aed4c063d4970a03250778da8041da9e0c83d8f22d2f1994da0ad72567ebd9","96357529d17c4690826d5d4c74deac51743a5388733b3f04004d898f0635ef20","3e6360f83a95540aa2176d279ca4694513afb1e5116a7ffe591c6b5bcf3b9c3c","8e571d58794b9b44ae53c2c67bedef72c500e8adbb80aab7a5c263adcba55b1e")
|
Reference:
https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography