T1027.013 Encrypted/Encoded File |
GroupContagious Interview |
Contagious Interview has used hexadecimal string encoding to hide critical JavaScript module names, function names, and C2 URLs, which are decoded dynamically at runtime. |
T1027.013 Encrypted/Encoded File |
MalwareHexEval Loader |
HexEval Loader has encoded module names and C2 URLs as hexadecimal strings in attempts to evade analysis. |
T1036.005 Match Legitimate Resource Name or Location |
MalwareHexEval Loader |
HexEval Loader has masqueraded and typosquatted as legitimate code repository packages and projects. |
T1041 Exfiltration Over C2 Channel |
MalwareHexEval Loader |
HexEval Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers. |
T1041 Exfiltration Over C2 Channel |
GroupContagious Interview |
Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers. |
T1059.007 JavaScript |
MalwareHexEval Loader |
HexEval Loader has executed malicious JavaScript code. |
T1071.001 Web Protocols |
MalwareHexEval Loader |
HexEval Loader has used HTTP and HTTPS POST requests to communicate with C2. |
T1105 Ingress Tool Transfer |
MalwareHexEval Loader |
HexEval Loader has been used to download a malicious payload to include BeaverTail. |
T1140 Deobfuscate/Decode Files or Information |
MalwareHexEval Loader |
HexEval Loader has decoded its payload prior to execution. |
T1204.005 Malicious Library |
GroupContagious Interview |
Contagious Interview has relied on users to install a malicious library from a code repository to infect the victim's device and has led to additional payload distribution and theft of sensitive data. |
T1571 Non-Standard Port |
GroupContagious Interview |
Contagious Interview has used TCP port 1224 for C2. |
T1583.001 Domains |
GroupContagious Interview |
Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2. |
T1583.006 Web Services |
GroupContagious Interview |
Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities. |
T1585 Establish Accounts |
GroupContagious Interview |
Contagious Interview has created and maintained personas on code repositories to distribute malicious payloads. |
T1587 Develop Capabilities |
GroupContagious Interview |
Contagious Interview developed malicious NPM packages for delivery to or retrieval by victims. |
T1608.001 Upload Malware |
GroupContagious Interview |
Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download. |