REF9403 is a DPRK-aligned activity cluster linked to the long-running Contagious Interview operation. It targets software developers, including developers in cryptocurrency and Web3 environments, using fraudulent recruiter outreach, job postings, and take-home coding challenges. Operators deliver trojanized but functional application repositories that execute concealed JavaScript malware when the project server is started. The payload is hidden in SVG assets using encoded fragments and reconstructed at runtime, providing defense evasion and reducing static detection opportunities. The malware is aligned with OTTERCOOKIE and operates across Windows, macOS, and Linux. It steals browser credentials, browser-session and wallet-extension data, cryptocurrency-wallet data, developer-relevant files and secrets, and clipboard contents. It also deploys a Socket.IO-based remote-access component capable of persistent command-and-control communications and operator shell-command execution; Windows infections may download and execute additional payloads. REF9403 creates supply-chain risk by compromising developer endpoints that may hold source-code access, cloud credentials, software secrets, and access to downstream organizational environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A DPRK-linked social-engineering campaign using fake recruiter job lures and trojanized coding challenge repositories to infect software developers, steal credentials, crypto wallet data, developer files, and provide backdoor shell access.
Developer-focused social-engineering campaign using fake job coding tests to deliver OTTERCOOKIE-aligned malware hidden in SVG image assets inside a working e-commerce project.
North Korea-linked activity cluster using fake recruiter lures and SVG comment-block steganography to deliver multi-component malware to developers.
Conducts Contagious Interview social-engineering campaigns against developers, using fake recruitment offers and functional but trojanized coding projects to steal browser credentials, cryptocurrency wallets, developer files, clipboard data, and establish Socket.IO-based remote access. The group conceals payload fragments in SVG image comments and executes them when the project server starts, creating potential supply-chain access through compromised developers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.