Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
MalwareBeaverTail | BeaverTail has added junk data or a dummy character prepended to a string to hamper decoding attempts. |
| T1005 Data from Local System |
MalwareBeaverTail | BeaverTail has exfiltrated data collected from local systems. |
| T1005 Data from Local System |
MalwareInvisibleFerret | InvisibleFerret has collected data utilizing a script that contained a list of excluded files and directory names and naming patterns of interest such as environment and configuration files, documents, spreadsheets, and other files that contained the words secret, wallet, private, and password. |
| T1016 System Network Configuration Discovery |
MalwareInvisibleFerret | InvisibleFerret has collected the local IP address, and external IP. |
| T1027.010 Command Obfuscation |
GroupContagious Interview | Contagious Interview has obfuscated JavaScript code using Base64 and variable substitutions. |
| T1027.013 Encrypted/Encoded File |
MalwareInvisibleFerret | InvisibleFerret has utilized the XOR and Base64 encoding for each of its modules. InvisibleFerret has also obfuscated files with a combination of zlib, Base64 and reverse string order. InvisibleFerret has also utilized the XOR and Base64 encoding some of its Python scripts. |
| T1027.013 Encrypted/Encoded File |
MalwareBeaverTail | BeaverTail has obfuscated strings of code with Base64 encoding within the JavaScript version of the malware. BeaverTail has also utilized the open-source tool JavaScript-Obfuscator to obfuscate strings and functions. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1033 System Owner/User Discovery |
MalwareInvisibleFerret | InvisibleFerret has identified the user’s UUID and username through the "pay" module. |
| T1036 Masquerading |
GroupContagious Interview | Contagious Interview has delivered BeaverTail malware masquerading as legitimate software or applications. Contagious Interview has also delivered malicious payloads masquerading as legitimate software drivers. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Sekoia ClickFake 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1041 Exfiltration Over C2 Channel |
GroupContagious Interview | Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025SecurityScorecard Contagious Interview October 2024Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupContagious Interview | Contagious Interview has exfiltrated victim information using FTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareInvisibleFerret | InvisibleFerret has used FTP to exfiltrate files and directories using the command `ssh_upload` which contains with six subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr` and `sfind` that had varying functions. InvisibleFerret has exfiltrated stolen files and data to the C2 servers over ports 1224, 2245 and 8637. |
| T1056.001 Keylogging |
MalwareInvisibleFerret | InvisibleFerret has conducted keylogging using the Python project “pyWinHook” and "Pyhook". InvisibleFerret has also captured keylogging thread checks for changes in an active window and key presses. |
| T1059.001 PowerShell |
MalwareInvisibleFerret | InvisibleFerret has utilized a PowerShell script created in the victim’s home directory named “conf.ps1” that is used to modify configuration files for AnyDesk remote services. |
| T1059.006 Python |
MalwareInvisibleFerret | InvisibleFerret is written in Python and has used Python scripts for execution. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1059.006 Python |
GroupContagious Interview | Contagious Interview has used the Python-based malware such as InvisibleFerret to install and execute Python Packages and Python modules. |
| T1059.007 JavaScript |
MalwareBeaverTail | BeaverTail has executed malicious JavaScript code. BeaverTail has also been compiled with the Qt framework to execute in both Windows and macOS. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1071.001 Web Protocols |
MalwareInvisibleFerret | InvisibleFerret has used HTTP for C2 communications. |
| T1074.001 Local Data Staging |
MalwareInvisibleFerret | InvisibleFerret has staged data in consolidated folders prior to exfiltration. |
| T1082 System Information Discovery |
MalwareBeaverTail | BeaverTail has been known to collect basic system information. BeaverTail has also collected data to include hostname and current timestamp prior to uploading data to the API endpoint `/uploads` on the C2 server. |
| T1082 System Information Discovery |
MalwareInvisibleFerret | InvisibleFerret has collected OS type, hostname and system version through the "pay" module. InvisibleFerret has also queried the victim device using Python scripts to obtain the User and Hostname. |
| T1083 File and Directory Discovery |
GroupContagious Interview | Contagious Interview has conducted key word searches within files and directories on a compromised hosts to identify files for exfiltration. |
| T1083 File and Directory Discovery |
MalwareInvisibleFerret | InvisibleFerret has identified specific directories and files for exfiltration using the `ssh_upload` command which contains subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr`, `sfind`. InvisibleFerret also has the capability to scan and upload files of interest from multiple OS systems through the use of scripts that check file names, file extensions, and avoids certain path names. InvisibleFerret has utilized the `findstr` on Windows or the macOS `find` commands to search for files of interest. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1083 File and Directory Discovery |
MalwareBeaverTail | BeaverTail has searched for .ldb and .log files stored in browser extension directories for collection and exfiltration. |
| T1095 Non-Application Layer Protocol |
MalwareInvisibleFerret | InvisibleFerret has established a connection with the C2 server over TCP traffic. InvisibleFerret has also created a TCP reverse shell communicating via a socket connection over ports 1245, 80, 2245, 3001, and 5000. |
| T1105 Ingress Tool Transfer |
MalwareInvisibleFerret | InvisibleFerret has downloaded “AnyDesk.exe” into the user’s home directory from the C2 server when checks for the service fail to identify its presence in the victim environment. InvisibleFerret has also been configured to download additional payloads using a command which calls to the /bow URI. |
| T1105 Ingress Tool Transfer |
MalwareBeaverTail | BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1115 Clipboard Data |
MalwareInvisibleFerret | InvisibleFerret has stolen data from the clipboard using the Python project “pyperclip”. InvisibleFerret has also captured clipboard contents during copy and paste operations. |
| T1124 System Time Discovery |
MalwareBeaverTail | BeaverTail has obtained and sent the current timestamp associated with the victim device to C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareInvisibleFerret | InvisibleFerret has decoded XOR-encrypted and Base-64-encoded payloads prior to execution. |
| T1204.002 Malicious File |
MalwareBeaverTail | BeaverTail has been executed through lures involving malicious JavaScript projects or trojanized remote conferencing software such as MicroTalk or FreeConference. BeaverTail has also been executed through macOS and Windows installers disguised as chat applications. |
| T1204.005 Malicious Library |
GroupContagious Interview | Contagious Interview has relied on users to install a malicious library from a code repository to infect the victim's device and has led to additional payload distribution and theft of sensitive data. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023Securonix Contagious Interview DEVPOPPER April 2024Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1217 Browser Information Discovery |
MalwareBeaverTail | BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1219 Remote Access Tools |
MalwareInvisibleFerret | InvisibleFerret has utilized remote access software including AnyDesk client through the “adc” module. InvisibleFerret has also downloaded the AnyDesk client should it not already exist on the compromised host by searching for `C:/Program Files(x86)/AnyDesk/AnyDesk.exe`. |
| T1219.002 Remote Desktop Software |
GroupContagious Interview | Contagious Interview has downloaded remote management and monitoring software such as “AnyDesk” for post compromise activities. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024SecurityScorecard Contagious Interview October 2024 |
| T1489 Service Stop |
MalwareInvisibleFerret | InvisibleFerret has terminated Chrome and Brave browsers using the `taskkill` command on Windows and the `killall` command on other systems such as Linux and macOS. InvisibleFerret has also utilized it’s `ssh_kill` command to terminate Chrome and Brave browser processes. |
| T1555 Credentials from Password Stores |
MalwareBeaverTail | BeaverTail has collected keys stored for Solana stored in `.config/solana/id.json` and other login details associated with macOS within `/Library/Keychains/login.keychain` or for Linux within `/.local/share/keyrings`. |
| T1555.001 Keychain |
MalwareBeaverTail | BeaverTail has collected keys associated with macOS within `/Library/Keychains/login.keychain`. |
| T1555.003 Credentials from Web Browsers |
MalwareBeaverTail | BeaverTail has stolen passwords saved in web browsers. BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from `/.mozilla/firefox/` for exfiltration. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1555.003 Credentials from Web Browsers |
MalwareInvisibleFerret | InvisibleFerret has stolen login data, autofill data, cryptocurrency wallets, and payment information saved in web browsers such as Chrome, Brave, Opera, Yandex and Edge, to include versions affiliated with major operating systems on Windows, Linux, and macOS. InvisibleFerret has also leveraged the command `ssh_zcp` to copy browser data to include extensions and cryptocurrency wallet data. |
| T1555.005 Password Managers |
MalwareInvisibleFerret | InvisibleFerret has utilized the command `ssh_zcp` to exfiltrate data from browser extensions and password managers via Telegram and FTP. |
| T1560.001 Archive via Utility |
MalwareInvisibleFerret | InvisibleFerret has used 7zip, RAR and zip files to archive collected data for exfiltration. |
| T1564.003 Hidden Window |
MalwareInvisibleFerret | InvisibleFerret has executed Python instances of the browser module “.n2/bow” utilizing the `CREATE_NO_WINDOW` process creation flag. |
| T1566.003 Spearphishing via Service |
GroupContagious Interview | Contagious Interview has used fake job advertisements and messages sent via social media to spearphish targets. Contagious Interview has also leveraged hiring websites to solicit victims. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025SecurityScorecard Contagious Interview FamousChollima October 2024SecurityScorecard Contagious Interview October 2024Sekoia ClickFake 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| T1567 Exfiltration Over Web Service |
GroupContagious Interview | Contagious Interview has leveraged Telegram API to exfiltrate stolen data. |
| T1567 Exfiltration Over Web Service |
MalwareInvisibleFerret | InvisibleFerret has leveraged Telegram chat to upload stolen data using the Telegram API with a bot token. |
| T1571 Non-Standard Port |
MalwareBeaverTail | BeaverTail has communicated with C2 IP addresses over ports 1224 or 1244. |
| T1583.001 Domains |
GroupContagious Interview | Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2. ESET Contagious Interview BeaverTail InvisibleFerret February 2025PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Sekoia ClickFake 2025Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| T1585 Establish Accounts |
GroupContagious Interview | Contagious Interview has created and maintained personas on code repositories to distribute malicious payloads. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| T1585.001 Social Media Accounts |
GroupContagious Interview | Contagious Interview has created fake social media accounts such as LinkedIn and Telegram accounts for their targeting efforts. ESET Contagious Interview BeaverTail InvisibleFerret February 2025PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025SecurityScorecard Contagious Interview FamousChollima October 2024SecurityScorecard Contagious Interview October 2024Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
Showing the first 50.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.