0
Contagious Interview malware in SVG images: DPRK campaign
(www.elastic.co)
For [Blue|Purple] Teams in Cyber Defence - covering discovery, detection, response, threat intelligence, malware, offensive tradecraft and tooling, deception, reverse engineering etc.
"Stenography".
If you scroll down to the "SVG image file with Base64-encoded data" you can see on the right hand side that it's just a binary dump put into the svg via a comment. And also the js snippet just looks for that single comment and puts those together. t's not even split up and used as id string or something (where random strings would be plausible). Boring! Booo! Cheap!!
And tbh I'm not sure what the antivirus is supposed to look for? Things that could be random but are actually a binary dump? Someone please enlighten me.
I suppose it's clever in the sense that people who are actively looking for a job and stressed aren't going to look at random assets of a take home for a job.