REF9403 is a DPRK-aligned activity cluster associated with the long-running Contagious Interview operation. It targets software developers through recruiter-themed social engineering, including fake job offers and trojanized coding challenges, with particular emphasis on developers working in cryptocurrency and Web3 environments. The operation has been linked to North Korea with medium-to-high confidence based on code overlap, behavioral similarities, and infrastructure relationships with OTTERCOOKIE-related activity. The cluster’s tradecraft centers on initial access through direct engagement with developer communities, then delivery of malicious but functional project repositories that appear to be legitimate coding assignments. In observed cases, the repositories concealed malware payload fragments inside SVG image assets using steganographic techniques, with helper code reconstructing and executing the payload when the local development server started. This approach enables stealthy execution while preserving expected application behavior, increasing the likelihood that targets will run the project without suspicion. REF9403’s malware toolkit is modular and cross-platform, affecting Windows, macOS, and Linux. Reported capabilities include browser credential theft, cryptocurrency wallet theft, theft of developer files such as keys, configuration data, source code, and cloud-related artifacts, clipboard monitoring and theft, and remote shell access through a Socket.IO-based backdoor. Additional behaviors reported in OTTERCOOKIE-aligned payloads include virtual-machine or sandbox awareness and, on Windows, the ability to download and execute additional payloads. The activity presents elevated supply-chain risk because compromised developers may inadvertently redistribute backdoored repositories or expose source-code access, cloud credentials, browser sessions, and wallet data. Known associated naming includes Contagious Interview and OTTERCOOKIE. REF9403 appears to represent a tracked campaign or sub-cluster within that broader North Korean developer-targeting ecosystem. Its dominant objective is financially motivated theft, especially theft of cryptocurrency and access to high-value developer environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A DPRK-linked social-engineering campaign using fake recruiter job lures and trojanized coding challenge repositories to infect software developers, steal credentials, crypto wallet data, developer files, and provide backdoor shell access.
Developer-focused social-engineering campaign using fake job coding tests to deliver OTTERCOOKIE-aligned malware hidden in SVG image assets inside a working e-commerce project.
North Korea-linked activity cluster using fake recruiter lures and SVG comment-block steganography to deliver multi-component malware to developers.
North Korean state-sponsored activity targeting software developers with fake job postings and coding challenges, using trojanized repositories and steganography in SVG files to deliver multi-stage malware for credential theft, crypto wallet theft, file theft, clipboard theft, and persistent remote access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.