Threat group.View on attack.mitre.org
Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrency-related activities.
| Technique | Procedure example |
|---|---|
| T1027.010 Command Obfuscation |
Contagious Interview has obfuscated JavaScript code using Base64 and variable substitutions. |
| T1027.013 Encrypted/Encoded File |
Contagious Interview has used hexadecimal string encoding to hide critical JavaScript module names, function names, and C2 URLs, which are decoded dynamically at runtime. |
| T1036 Masquerading |
Contagious Interview has delivered BeaverTail malware masquerading as legitimate software or applications. Contagious Interview has also delivered malicious payloads masquerading as legitimate software drivers. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Sekoia ClickFake 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1041 Exfiltration Over C2 Channel |
Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025SecurityScorecard Contagious Interview October 2024Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
Contagious Interview has exfiltrated victim information using FTP. |
| T1059.003 Windows Command Shell |
Contagious Interview has utilized VBS scripts to open cmd.exe and run commands to include the go_batch.bat batch file. |
| T1059.004 Unix Shell |
Contagious Interview has targeted macOS victim hosts using a bash downloader coremedia.sh and a bash script cloud.sh. |
| T1059.005 Visual Basic |
Contagious Interview has utilized Visual Basic scripts in the execution of their downloader malware targeting Windows devices including as script called update.vbs. |
| T1059.006 Python |
Contagious Interview has used the Python-based malware such as InvisibleFerret to install and execute Python Packages and Python modules. |
| T1059.007 JavaScript |
Contagious Interview has leveraged JavaScript in the execution of their downloader malware targeting Windows devices using a NodeJS script titled nvidia.js. |
| T1070.004 File Deletion |
Contagious Interview has configured malware to remove archives used in collection activities following successful exfiltration. |
| T1071.003 Mail Protocols |
Contagious Interview has utilized email notifications from malware distribution servers to track victim engagement. |
| T1082 System Information Discovery |
Contagious Interview has configured malicious webpages to identify the victim’s operating system by reviewing the details of the victims User-Agent of their browser. |
| T1083 File and Directory Discovery |
Contagious Interview has conducted key word searches within files and directories on a compromised hosts to identify files for exfiltration. |
| T1090 Proxy |
Contagious Interview has leveraged Astrill VPN for C2. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.