{"id":14424,"date":"2026-07-20T10:03:39","date_gmt":"2026-07-20T10:03:39","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/07\/20\/north-korean-hackers-hide-ottercookie-malware-in-svg-images-to-backdoor-developers\/"},"modified":"2026-07-20T10:03:39","modified_gmt":"2026-07-20T10:03:39","slug":"north-korean-hackers-hide-ottercookie-malware-in-svg-images-to-backdoor-developers","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/07\/20\/north-korean-hackers-hide-ottercookie-malware-in-svg-images-to-backdoor-developers\/","title":{"rendered":"North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers"},"content":{"rendered":"<p>    North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">North Korean-linked hackers are hiding OTTERCOOKIE-aligned malware inside ordinary SVG flag images, turning a familiar part of a web project into a concealed delivery channel. <\/p>\n<p class=\"wp-block-paragraph\">The operation targets software developers who believe they are completing a coding test for a job opportunity.<a href=\"https:\/\/thehackernews.com\/2026\/07\/north-korea-linked-hackers-hide.html\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">The victims receive a working e-commerce project through social-engineering messages, then are asked to run it locally. <\/p>\n<p class=\"wp-block-paragraph\">Although the application appears legitimate, its assets contain fragments of malicious code that are quietly rebuilt when the server starts.<a href=\"https:\/\/thehackernews.com\/2026\/07\/north-korea-linked-hackers-hide.html\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">StepSecurity analysts have noted the growing danger of developer-focused attacks that hide harmful behavior until code is executed. <\/p>\n<p class=\"wp-block-paragraph\">In this case, <a href=\"https:\/\/www.stepsecurity.io\/blog\/sleepergem-compromised-rubygems-drop-persistent-backdoor\" data-type=\"link\" data-id=\"https:\/\/www.stepsecurity.io\/blog\/sleepergem-compromised-rubygems-drop-persistent-backdoor\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Elastic Security Labs and StepSecurity said in a report<\/a> shared with Cyber Security News (CSN) that the activity is tracked as REF9403 and is linked to the long-running Contagious Interview operation.<\/p>\n<p class=\"wp-block-paragraph\">The impact can be severe because developer machines often hold browser sessions, source-code access, cloud keys, and cryptocurrency wallets. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEghxiehy1AaynZugluTsyFd3bsWGu__-7LNvo7gGuztfsST61RggUkycACaEpPImLqi0VsfULkbEPImSbrOs61XzKm1sbD8RNKGf7fkHgLphB4xTdq-E7bKAhESqZNTgfrsqcPBj9sJH_qK-HUjgrdGYtFb1v1EvYzvWlevj8hRMHEUEMKk_1HApvcNHK4\/s1600\/Dendreo%2520repository%2520%28Source%2520-%2520StepSecurity%29.webp?ssl=1\" alt=\"Dendreo repository (Source - StepSecurity)\"><figcaption class=\"wp-element-caption\">Dendreo repository (Source \u2013 StepSecurity)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">A single test project can therefore give attackers a route to valuable personal and corporate data without exploiting a software flaw.<a href=\"https:\/\/thehackernews.com\/2026\/07\/north-korea-linked-hackers-hide.html\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 id=\"h-north-korean-hackers-hide-ottercookie-malware\" class=\"wp-block-heading\"><strong>North Korean Hackers Hide OTTERCOOKIE Malware<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The attackers used SVG files depicting country flags, including AE.svg and AF.svg, in the project\u2019s assets folder. <\/p>\n<p class=\"wp-block-paragraph\">Each image looked harmless, but HTML comment blocks held Base64-encoded pieces of the payload, allowing the malware to avoid obvious inspection and security scanning.<a href=\"https:\/\/thehackernews.com\/2026\/07\/north-korea-linked-hackers-hide.html\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">A JavaScript file named serverValidation.js reads the SVG files, joins the fragments, and executes the recovered code. <\/p>\n<p class=\"wp-block-paragraph\">The project remains functional, which makes the trap harder to spot, while the hidden routine runs automatically whenever the server boots.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhn7F-fOemr4zqnSpckzTmyZoeDvct04aWfmoRDvNdXmbTesj5tDz4Yhp1h-LW6fQi-1WLiqW2vICG7ydvcmaRliHKg2fw3msKOG0FORT73kdITjBFPzs4t3pPJ7p_bX5J8y8PlK0Q9oXEDmRQ5U5SKoYggzo1990OsHvXGF8vbxq0wgHAJXwsJhyphenhyphentv8Sc\/s1600\/Fastlane%2520plugin%2520repository%2520%28Source%2520-%2520StepSecurity%29.webp?ssl=1\" alt=\"Fastlane plugin repository (Source - StepSecurity)\"><figcaption class=\"wp-element-caption\">Fastlane plugin repository (Source \u2013 StepSecurity)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">The recovered toolkit has four main parts: a browser credential and cryptocurrency-wallet stealer, a file stealer, a clipboard collector, and a remote-access component using Socket.IO. <\/p>\n<p class=\"wp-block-paragraph\">Together, they can collect sensitive information and give an operator a way to run commands on an infected system.<a href=\"https:\/\/thehackernews.com\/2026\/07\/north-korea-linked-hackers-hide.html\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">This approach expands on the group\u2019s familiar fake-interview playbook, which has also used malicious packages and fabricated developer portfolios. <\/p>\n<p class=\"wp-block-paragraph\">Readers tracking\u00a0<a href=\"https:\/\/cybersecuritynews.com\/north-korean-hackers-exploiting-npm\/\" target=\"_blank\" rel=\"noreferrer noopener\">North Korean npm campaign activity<\/a>\u00a0can see how the same broader focus on developers has moved across repositories, package registries, and hosting services.<a href=\"https:\/\/cybersecuritynews.com\/north-korean-hackers-exploiting-npm\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 id=\"h-fake-tests-raise-risk\" class=\"wp-block-heading\"><strong>Fake Tests Raise Risk<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The campaign reportedly began with job messages posted in a community Slack channel, followed by direct contact and a request to finish a coding assessment. <\/p>\n<p class=\"wp-block-paragraph\">This routine recruitment-style interaction is important because it gives the project a credible reason to be downloaded and executed.<a href=\"https:\/\/thehackernews.com\/2026\/07\/north-korea-linked-hackers-hide.html\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">Organizations should treat unsolicited coding tasks as untrusted software, even when their code looks polished and the application works as promised. <\/p>\n<p class=\"wp-block-paragraph\">Before running one, developers should review server startup files and asset directories, and look closely for dynamic code execution such as eval() or code that reads image files.<a href=\"https:\/\/thehackernews.com\/2026\/07\/north-korea-linked-hackers-hide.html\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">Teams that have run a suspect project should isolate the device, review browser-stored credentials and wallet extensions, and rotate exposed API keys, SSH keys, cloud credentials, GitHub and npm tokens. <\/p>\n<p class=\"wp-block-paragraph\">This is especially important given\u00a0<a href=\"https:\/\/cybersecuritynews.com\/ottercookie-malware-upgraded-with-new-features\/\" target=\"_blank\" rel=\"noreferrer noopener\">OTTERCOOKIE credential theft features<\/a>, which include cross-platform collection capabilities.<\/p>\n<p class=\"wp-block-paragraph\">Network defenders should monitor or restrict connections to the identified rightwidth[.]dev infrastructure rather than relying only on install-script controls. <\/p>\n<p class=\"wp-block-paragraph\">The payload starts at server launch, so package-manager protections aimed at installation scripts may not stop it;\u00a0<a href=\"https:\/\/cybersecuritynews.com\/miasma-turns-trusted-npm-packages-into-persistent-backdoors\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious package supply-chain threats<\/a>\u00a0also show why dependency and repository review must extend beyond initial installation.<\/p>\n<p class=\"wp-block-paragraph\">Security teams can add checks that flag eval() in server-side JavaScript and inspect SVG comments for unusual encoded content. <\/p>\n<p class=\"wp-block-paragraph\">They should also search project folders and download histories for the known archive names and serverValidation.js, then preserve evidence before rebuilding systems where the scope of exposure is unclear.<a href=\"https:\/\/thehackernews.com\/2026\/07\/north-korea-linked-hackers-hide.html\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">The incident is another reminder that image files and other static assets are not automatically safe. <\/p>\n<p class=\"wp-block-paragraph\">Developers should verify the sender, inspect every part of an assessment repository, and avoid executing code from a job offer until it has been independently reviewed, particularly amid\u00a0<a href=\"https:\/\/cybersecuritynews.com\/hackers-use-fake-gemini-npm-package\/\" target=\"_blank\" rel=\"noreferrer noopener\">developer credential theft campaigns<\/a>.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Indicators of Compromise (IoCs):-<\/strong><\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Indicator<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>File name<\/td>\n<td><code>AE.svg<\/code><\/td>\n<td>SVG country-flag asset used to hold Base64-encoded payload fragments\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/07\/north-korea-linked-hackers-hide.html\"><\/a>\n<\/td>\n<\/tr>\n<tr>\n<td>File name<\/td>\n<td><code>AF.svg<\/code><\/td>\n<td>SVG country-flag asset used to hold Base64-encoded payload fragments\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/07\/north-korea-linked-hackers-hide.html\"><\/a>\n<\/td>\n<\/tr>\n<tr>\n<td>File name<\/td>\n<td><code>serverValidation.js<\/code><\/td>\n<td>JavaScript file that reconstructs and executes the hidden payload\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/07\/north-korea-linked-hackers-hide.html\"><\/a>\n<\/td>\n<\/tr>\n<tr>\n<td>File name<\/td>\n<td><code>next-ecommerce-private-main.zip<\/code><\/td>\n<td>Identified malicious project archive\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/app.stepsecurity.io\/action-advisor?page=93\"><\/a>\n<\/td>\n<\/tr>\n<tr>\n<td>File name<\/td>\n<td><code>shopping-platform-main.zip<\/code><\/td>\n<td>Identified malicious project archive\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/app.stepsecurity.io\/action-advisor?page=93\"><\/a>\n<\/td>\n<\/tr>\n<tr>\n<td>File name<\/td>\n<td><code>ecommerce-platform.zip<\/code><\/td>\n<td>Identified malicious project archive\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/app.stepsecurity.io\/action-advisor?page=93\"><\/a>\n<\/td>\n<\/tr>\n<tr>\n<td>File name<\/td>\n<td><code>ecommerce-platform-main.zip<\/code><\/td>\n<td>Identified malicious project archive\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/app.stepsecurity.io\/action-advisor?page=93\"><\/a>\n<\/td>\n<\/tr>\n<tr>\n<td>File name<\/td>\n<td><code>shopping-platform.rar<\/code><\/td>\n<td>Identified malicious project archive\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/app.stepsecurity.io\/action-advisor?page=93\"><\/a>\n<\/td>\n<\/tr>\n<tr>\n<td>File name<\/td>\n<td><code>shop-main.zip<\/code><\/td>\n<td>Identified malicious project archive\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/app.stepsecurity.io\/action-advisor?page=93\"><\/a>\n<\/td>\n<\/tr>\n<tr>\n<td>File name<\/td>\n<td><code>ecommerce-main.zip<\/code><\/td>\n<td>Identified malicious project archive\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/app.stepsecurity.io\/action-advisor?page=93\"><\/a>\n<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td><code>rightwidth[.]dev<\/code><\/td>\n<td>Malicious infrastructure cluster associated with the campaign\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/app.stepsecurity.io\/action-advisor?page=93\"><\/a>\n<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td><code>ldb.rightwidth[.]dev<\/code><\/td>\n<td>Confirmed command-and-control subdomain\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/app.stepsecurity.io\/action-advisor?page=93\"><\/a>\n<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td><code>upload.rightwidth[.]dev<\/code><\/td>\n<td>Confirmed command-and-control subdomain\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/app.stepsecurity.io\/action-advisor?page=93\"><\/a>\n<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td><code>controller.rightwidth[.]dev<\/code><\/td>\n<td>Confirmed command-and-control subdomain\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/app.stepsecurity.io\/action-advisor?page=93\"><\/a>\n<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td><code>file.rightwidth[.]dev<\/code><\/td>\n<td>Confirmed command-and-control subdomain\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/app.stepsecurity.io\/action-advisor?page=93\"><\/a>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong>\u00a0<em>IP addresses and domains are intentionally defanged (e.g.,\u00a0<\/em><code><em>[.]<\/em><\/code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM<\/em>.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Strengthen Your SOC by Accelerating Threat Detection &amp; Rapid Investigations.\u00a0-&gt;\u00a0<a href=\"https:\/\/any.run\/enterprise\/?utm_source=csn&amp;utm_medium=links&amp;utm_campaign=sandbox&amp;utm_content=enterprise&amp;utm_term=0626#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener\">Integrate ANY.RUN With Your SOC\u00a0<\/a><strong><a href=\"https:\/\/any.run\/enterprise\/?utm_source=csn&amp;utm_medium=links&amp;utm_campaign=sandbox&amp;utm_content=enterprise&amp;utm_term=0626#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener\">Now<\/a><\/strong>.<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/north-korean-hackers-ottercookie-malware\/\">North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/north-korean-hackers-ottercookie-malware\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers North Korean-linked hackers are hiding OTTERCOOKIE-aligned malware inside ordinary SVG flag images, turning a familiar part of a web project into a concealed delivery channel. The operation targets software developers who believe they are completing a coding test for a job opportunity. The [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-14424","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14424"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=14424"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14424\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=14424"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=14424"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=14424"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}