
Phishing Link Could Plant a Rogue ChatGPT Agent
Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…
Researchers report a real North Korea–linked social engineering campaign where attackers posed as recruiters and sent fake job offers and coding assessments. The “test” materials hid a multi-stage malware payload inside SVG flag images, aiming to steal browser logins and crypto wallet data and install remote access tools. The campaign notably targeted a security firm’s community Slack with a bogus e-commerce developer role.
A North Korea linked campaign known as Contagious Interview used fake job offers and coding assessments as the lure. Targets were told to review or download SVG flag images as part of a required exercise for an e-commerce developer role. Hidden inside those image files, in comment blocks that many detection tools do not inspect closely, was a four-stage malware payload aligned with the OtterCookie family.
Once triggered, the payload steals browser credentials and crypto wallet data, exfiltrates files, and installs a Socket.IO-based remote access trojan. This gives attackers a foothold well beyond the initial job-application interaction, turning a routine hiring exercise into a full credential and data theft incident.
The pretext relied on the normalcy of technical hiring processes. Coding assessments and take-home tests are a standard part of developer recruiting, so a request to review or download provided assets did not look unusual on its face. Using an uncommon delivery mechanism, image comment blocks inside SVG files, also helped the payload slip past some standard detection approaches that focus on more typical file types.
The campaign's reach into a security firm's own community Slack workspace, using a bogus e-commerce developer posting, shows how even security-aware communities can be targeted through channels that feel informal or trusted rather than through official recruiting systems.
Treat unsolicited job outreach, particularly through community Slack groups or similar informal channels, as a potential attack vector until the recruiter and role are verified through trusted, official sources. Be cautious with coding tests that require opening unusual assets, and where possible use separate, hardened, or disposable environments for any untrusted assessment materials rather than a primary work device. Because this payload is designed to steal browser credentials, crypto wallet data, and files while installing a remote access trojan, awareness training should specifically call out recruitment-themed lures as a credential theft and data exfiltration risk, not just a phishing nuisance.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
The malware payload was embedded inside SVG flag images using content placed in image comment blocks, which helped it evade some detection approaches.
The payload runs in four stages and is aligned with the OtterCookie family, stealing browser credentials and crypto wallets, exfiltrating files, and installing a Socket.IO-based remote access trojan.
The campaign targeted developers, security engineers, and job seekers, and notably reached a security firm's community Slack workspace through a bogus e-commerce developer role.
Warning signs include unsolicited job outreach pressuring targets to open assessment files, unusual file types like SVGs required for a coding test, and recruitment messages arriving through community Slack channels instead of official hiring processes.
You get a Slack DM: “Hi, we’re hiring for an e‑commerce developer role, here’s the coding assessment and SVG flag images to use.” Looks legit, right? Researchers tracked a real campaign, called Contagious Interview, where SVG flag images in these “tests” hid a four‑stage OtterCookie malware payload that steals browser logins, crypto wallets, and files, then drops a remote access tool. Here’s the twist: the malware was stuffed into comment blocks inside those SVG flag files, shared right in a security firm’s own community Slack. Unsolicited job, weird SVG assets, coming from a public workspace, that combo is your red flag. If a recruiter contacts you in Slack or a community channel and wants you to open test assets like SVG flags, stop and verify the role and recruiter through official company channels before you open anything.

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

A North Korea-linked group is running fake recruitment campaigns to trick people into taking “online assessments” for jobs that don’t exist. The goal is to…

Researchers documented a real phishing operation that used Telegram “secret chats” to send fake security warnings to specific people, including an exiled…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

Microsoft reported that phishing tied to the Tycoon2FA phishing-as-a-service platform dropped sharply after a disruption, pushing attackers to change tactics…

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into…