ATT&CKGroupsContagious Interview

Contagious Interview

G1052

Threat group.View on attack.mitre.org

About this group

Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrency-related activities.

Techniques used54

Procedure examples54

TechniqueProcedure example
T1027.010
Command Obfuscation

Contagious Interview has obfuscated JavaScript code using Base64 and variable substitutions.

T1027.013
Encrypted/Encoded File

Contagious Interview has used hexadecimal string encoding to hide critical JavaScript module names, function names, and C2 URLs, which are decoded dynamically at runtime.

T1036
Masquerading

Contagious Interview has delivered BeaverTail malware masquerading as legitimate software or applications. Contagious Interview has also delivered malicious payloads masquerading as legitimate software drivers.

T1041
Exfiltration Over C2 Channel

Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

Contagious Interview has exfiltrated victim information using FTP.

T1059.003
Windows Command Shell

Contagious Interview has utilized VBS scripts to open cmd.exe and run commands to include the go_batch.bat batch file.

T1059.004
Unix Shell

Contagious Interview has targeted macOS victim hosts using a bash downloader coremedia.sh and a bash script cloud.sh.

T1059.005
Visual Basic

Contagious Interview has utilized Visual Basic scripts in the execution of their downloader malware targeting Windows devices including as script called update.vbs.

T1059.006
Python

Contagious Interview has used the Python-based malware such as InvisibleFerret to install and execute Python Packages and Python modules.

T1059.007
JavaScript

Contagious Interview has leveraged JavaScript in the execution of their downloader malware targeting Windows devices using a NodeJS script titled nvidia.js.

T1070.004
File Deletion

Contagious Interview has configured malware to remove archives used in collection activities following successful exfiltration.

T1071.003
Mail Protocols

Contagious Interview has utilized email notifications from malware distribution servers to track victim engagement.

T1082
System Information Discovery

Contagious Interview has configured malicious webpages to identify the victim’s operating system by reviewing the details of the victims User-Agent of their browser.

T1083
File and Directory Discovery

Contagious Interview has conducted key word searches within files and directories on a compromised hosts to identify files for exfiltration.

T1090
Proxy

Contagious Interview has leveraged Astrill VPN for C2.

View all 54 procedure examples

Software4

Campaigns0

None recorded.

References8

  1. Datadog Contagious Interview Tenacious Pungsan October 2024 Open source
    Ian Kretz, Sebastian Obregoso, Datadog Security Research Team. (2024, October 24). Tenacious Pungsan: A DPRK threat actor linked to Contagious Interview. Retrieved October 20, 2025.
  2. ESET Contagious Interview BeaverTail InvisibleFerret February 2025 Open source
    Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.
  3. Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024 Open source
    eSentire Threat Response Unit (TRU). (2024, November 14). Bored BeaverTail & InvisibleFerret Yacht Club – A Lazarus Lure Pt.2. Retrieved October 17, 2025.
  4. PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023 Open source
    Unit 42. (2023, November 21). Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors. Retrieved October 17, 2025.
  5. PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024 Open source
    Unit42. (2024, October 9). Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware. Retrieved October 17, 2025.
  6. Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025 Open source
    Insikt Group. (2025, February 13). Inside the Scam: North Korea’s IT Worker Threat. Retrieved October 17, 2025.
  7. Validin Contagious Interview North Korea ClickFix January 2025 Open source
    Efstratios Lontzetidis. (2025, January 16). Lazarus APT: Techniques for Hunting Contagious Interview. Retrieved October 20, 2025.
  8. Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 Open source
    Seongsu Park. (2024, November 4). From Pyongyang to Your Payroll: The Rise of North Korean Remote Workers in the West. Retrieved October 17, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.