T1036 Masquerading |
GroupContagious Interview |
Contagious Interview has delivered BeaverTail malware masquerading as legitimate software or applications. Contagious Interview has also delivered malicious payloads masquerading as legitimate software drivers. |
T1059.003 Windows Command Shell |
GroupContagious Interview |
Contagious Interview has utilized VBS scripts to open cmd.exe and run commands to include the go_batch.bat batch file. |
T1059.004 Unix Shell |
GroupContagious Interview |
Contagious Interview has targeted macOS victim hosts using a bash downloader coremedia.sh and a bash script cloud.sh. |
T1059.005 Visual Basic |
GroupContagious Interview |
Contagious Interview has utilized Visual Basic scripts in the execution of their downloader malware targeting Windows devices including as script called update.vbs. |
T1059.007 JavaScript |
GroupContagious Interview |
Contagious Interview has leveraged JavaScript in the execution of their downloader malware targeting Windows devices using a NodeJS script titled nvidia.js. |
T1082 System Information Discovery |
GroupContagious Interview |
Contagious Interview has configured malicious webpages to identify the victim’s operating system by reviewing the details of the victims User-Agent of their browser. |
T1204.004 Malicious Copy and Paste |
GroupContagious Interview |
Contagious Interview has leveraged ClickFix type tactics enticing victims to copy and paste malicious code. |
T1543.001 Launch Agent |
GroupContagious Interview |
Contagious Interview has established persistence using InvisibleFerret malware to create file to run the script on Startup via LaunchAgents. Contagious Interview has also utilized a plist file located in `/Library/LaunchAgents` to enable a malicious bash script the ability to persist. |
T1546.004 Unix Shell Configuration Modification |
GroupContagious Interview |
Contagious Interview has targeted macOS victim hosts using a bash downloader `coremedia.sh` and a bash script `cloud.sh`. |
T1555.001 Keychain |
GroupContagious Interview |
Contagious Interview has leveraged malware variants configured to dump credentials from the macOS keychain. |
T1566.003 Spearphishing via Service |
GroupContagious Interview |
Contagious Interview has used fake job advertisements and messages sent via social media to spearphish targets. Contagious Interview has also leveraged hiring websites to solicit victims. |
T1567.002 Exfiltration to Cloud Storage |
GroupContagious Interview |
Contagious Interview has exfiltrated stolen passwords to Dropbox. |
T1573.001 Symmetric Cryptography |
GroupContagious Interview |
Contagious Interview has encrypted C2 traffic using RC4. |
T1583.001 Domains |
GroupContagious Interview |
Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2. |
T1583.006 Web Services |
GroupContagious Interview |
Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities. |
T1589 Gather Victim Identity Information |
GroupContagious Interview |
Contagious Interview has researched specific professional groups such as software developers for targeting. Contagious Interview has also researched individuals who work in roles related to cryptocurrency and blockchain technologies. |
T1593.001 Social Media |
GroupContagious Interview |
Contagious Interview had identified and solicited victims through social media such as LinkedIn, X, and Telegram. |