Fake Job Tests Hide Malware in SVG “Flag” Images

About DFIR · High sophistication
Last updated July 30, 2026

Researchers report a real North Korea–linked social engineering campaign where attackers posed as recruiters and sent fake job offers and coding assessments. The “test” materials hid a multi-stage malware payload inside SVG flag images, aiming to steal browser logins and crypto wallet data and install remote access tools. The campaign notably targeted a security firm’s community Slack with a bogus e-commerce developer role.

How the Attack Worked

A North Korea linked campaign known as Contagious Interview used fake job offers and coding assessments as the lure. Targets were told to review or download SVG flag images as part of a required exercise for an e-commerce developer role. Hidden inside those image files, in comment blocks that many detection tools do not inspect closely, was a four-stage malware payload aligned with the OtterCookie family.

Once triggered, the payload steals browser credentials and crypto wallet data, exfiltrates files, and installs a Socket.IO-based remote access trojan. This gives attackers a foothold well beyond the initial job-application interaction, turning a routine hiring exercise into a full credential and data theft incident.

Why It Succeeded

The pretext relied on the normalcy of technical hiring processes. Coding assessments and take-home tests are a standard part of developer recruiting, so a request to review or download provided assets did not look unusual on its face. Using an uncommon delivery mechanism, image comment blocks inside SVG files, also helped the payload slip past some standard detection approaches that focus on more typical file types.

The campaign's reach into a security firm's own community Slack workspace, using a bogus e-commerce developer posting, shows how even security-aware communities can be targeted through channels that feel informal or trusted rather than through official recruiting systems.

What to Watch For

  • Unsolicited recruiting messages, especially inside Slack or other community channels, asking you to complete an assessment
  • Coding tests or take-home assignments that require opening or downloading unusual file types, including image formats like SVG
  • Job outreach that arrives outside a company's official hiring channels or careers site
  • Pressure to interact quickly with provided "test" files or assets before verifying the opportunity

Building Resistance

Treat unsolicited job outreach, particularly through community Slack groups or similar informal channels, as a potential attack vector until the recruiter and role are verified through trusted, official sources. Be cautious with coding tests that require opening unusual assets, and where possible use separate, hardened, or disposable environments for any untrusted assessment materials rather than a primary work device. Because this payload is designed to steal browser credentials, crypto wallet data, and files while installing a remote access trojan, awareness training should specifically call out recruitment-themed lures as a credential theft and data exfiltration risk, not just a phishing nuisance.

Related technique reference: T1566.003, T1204.001.

Key findings

  • North Korea–linked actors used fake job offers and coding assessments to deliver malware (Contagious Interview).
  • The malware was hidden inside SVG flag images using content in image comment blocks to evade some detection approaches.
  • The payload is described as four stages and aligned with the OtterCookie family.
  • Impact described includes stealing browser credentials and crypto wallets, file exfiltration, and installation of a Socket.IO-based remote access trojan.
  • The campaign “first surfacing” included targeting a security firm’s community Slack with a fake e-commerce developer role.

Who’s being targeted

  • Commonly targeted roles: Engineering (Developers), Security team, Recruiting / Talent Acquisition, Anyone active in professional community Slack groups.
  • Affected industries: Professional Services, Information Technology, Software / Engineering.
  • Attack channels: slack, website.
  • Impersonated: Recruiter / hiring team for an e-commerce developer role.

Red flags to watch for

  • Unsolicited job outreach with pressure to open “assessment” files or assets
  • Unusual file types (e.g., SVG images) included as required test inputs
  • Recruitment message coming via a community Slack rather than official hiring channels
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers hide malware in SVG images?

The malware payload was embedded inside SVG flag images using content placed in image comment blocks, which helped it evade some detection approaches.

What happens if the malicious coding assessment is opened?

The payload runs in four stages and is aligned with the OtterCookie family, stealing browser credentials and crypto wallets, exfiltrating files, and installing a Socket.IO-based remote access trojan.

Who was targeted in this campaign?

The campaign targeted developers, security engineers, and job seekers, and notably reached a security firm's community Slack workspace through a bogus e-commerce developer role.

What are the red flags of this type of attack?

Warning signs include unsolicited job outreach pressuring targets to open assessment files, unusual file types like SVGs required for a coding test, and recruitment messages arriving through community Slack channels instead of official hiring processes.

Read the video transcript

You get a Slack DM: “Hi, we’re hiring for an e‑commerce developer role, here’s the coding assessment and SVG flag images to use.” Looks legit, right? Researchers tracked a real campaign, called Contagious Interview, where SVG flag images in these “tests” hid a four‑stage OtterCookie malware payload that steals browser logins, crypto wallets, and files, then drops a remote access tool. Here’s the twist: the malware was stuffed into comment blocks inside those SVG flag files, shared right in a security firm’s own community Slack. Unsolicited job, weird SVG assets, coming from a public workspace, that combo is your red flag. If a recruiter contacts you in Slack or a community channel and wants you to open test assets like SVG flags, stop and verify the role and recruiter through official company channels before you open anything.

Similar attacks

Fake Job Interview Lure Targets Crypto Staff

Fake Job Interview Lure Targets Crypto Staff

A North Korea-linked group is running fake recruitment campaigns to trick people into taking “online assessments” for jobs that don’t exist. The goal is to…

July 30, 2026