ATT&CKReferencesRecorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025

Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025

Insikt Group. (2025, February 13). Inside the Scam: North Korea’s IT Worker Threat. Retrieved October 17, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
GroupContagious Interview

Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers.

T1059.006
Python
MalwareInvisibleFerret

InvisibleFerret is written in Python and has used Python scripts for execution.

T1059.007
JavaScript
MalwareBeaverTail

BeaverTail has executed malicious JavaScript code. BeaverTail has also been compiled with the Qt framework to execute in both Windows and macOS.

T1082
System Information Discovery
MalwareInvisibleFerret

InvisibleFerret has collected OS type, hostname and system version through the "pay" module. InvisibleFerret has also queried the victim device using Python scripts to obtain the User and Hostname.

T1087.001
Local Account
MalwareInvisibleFerret

InvisibleFerret has queried the victim device using Python scripts to obtain the User and Hostname.

T1090
Proxy
GroupContagious Interview

Contagious Interview has leveraged Astrill VPN for C2.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareBeaverTail

BeaverTail has been hosted on code repositories and disseminated to victims through NPM packages.

T1204.001
Malicious Link
GroupContagious Interview

Contagious Interview has lured victims to click on a malicious link that led to download of a malicious payload. Contagious Interview has also leveraged links to malicious payloads on social media and code repositories.

T1217
Browser Information Discovery
MalwareBeaverTail

BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets.

T1566.003
Spearphishing via Service
GroupContagious Interview

Contagious Interview has used fake job advertisements and messages sent via social media to spearphish targets. Contagious Interview has also leveraged hiring websites to solicit victims.

T1583
Acquire Infrastructure
GroupContagious Interview

Contagious Interview has used services such as Astrill VPN.

T1583.001
Domains
GroupContagious Interview

Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2.

T1583.003
Virtual Private Server
GroupContagious Interview

Contagious Interview has acquired virtual private servers from services such as Stark Industries Solutions and RouterHosting. Contagious Interview has also utilized hosting providers to include Tier[.]Net, Majestic Hosting, Leaseweb Singapore, and Kaopu Cloud.

T1583.006
Web Services
GroupContagious Interview

Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities.

T1585.001
Social Media Accounts
GroupContagious Interview

Contagious Interview has created fake social media accounts such as LinkedIn and Telegram accounts for their targeting efforts.

T1585.002
Email Accounts
GroupContagious Interview

Contagious Interview has created fake email accounts to correspond with social media accounts, fake LinkedIn personas, code repository accounts, and job announcements on development job board services. Contagious Interview has also utilized fake email accounts with Threat Intelligence vendor services.

T1588.007
Artificial Intelligence
GroupContagious Interview

Contagious Interview has appeared to have used AI to generate images and content to facilitate their campaigns.

T1608.001
Upload Malware
GroupContagious Interview

Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download.

T1657
Financial Theft
MalwareBeaverTail

BeaverTail has searched the victim device for browser extensions commonly associated with cryptocurrency wallets.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.