Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
조작된 코딩 테스트를 통해 북한 해커들이 SVG 이미지에 악성코드를 숨긴 것으로 나타났다.
북한의 위협 행위자들이 조작된 채용 공고와 코딩 테스트를 통해 SVG 이미지 파일에 스테가노그래피를 사용하여 악성 페이로드를 숨기는 사례가 포착되었다. 이 공격은 OTTERCOOKIE와 관련된 네 단계의 페이로드로, 브라우저 자격 증명 및 암호화폐 지갑 탈취, 파일 탈취 등의 기능을 포함하고 있다. 사용자들이 이 프로젝트를 실행하면 이러한 악성코드에 감염될 위험이 있다.
Fake coding tests used by North Korean hackers to hide malware in SVG images.
North Korean threat actors have been observed using steganography in SVG image files to conceal malicious payloads as part of a campaign involving fake job postings and coding tests. This attack is aligned with OTTERCOOKIE, consisting of a four-stage payload that includes a browser credential and crypto wallet stealer, along with a file stealer. Users running the project face a risk of infection from these malicious codes.