ATT&CKReferencesSocket HexEval BeaverTail Contagious Interview June 2025

Socket HexEval BeaverTail Contagious Interview June 2025

Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples32

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareHexEval Loader

HexEval Loader has leveraged server-side client configurations to identify the public IP of the victim host.

T1027.013
Encrypted/Encoded File
MalwareHexEval Loader

HexEval Loader has encoded module names and C2 URLs as hexadecimal strings in attempts to evade analysis.

T1033
System Owner/User Discovery
MalwareHexEval Loader

HexEval Loader has collected the username from the victim host.

T1036.005
Match Legitimate Resource Name or Location
MalwareHexEval Loader

HexEval Loader has masqueraded and typosquatted as legitimate code repository packages and projects.

T1041
Exfiltration Over C2 Channel
MalwareHexEval Loader

HexEval Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers.

T1041
Exfiltration Over C2 Channel
GroupContagious Interview

Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers.

T1056.001
Keylogging
MalwareHexEval Loader

HexEval Loader has utilized a cross-platform keylogger that has the capability to capture keystrokes on Windows, macOS and Linux systems.

T1059.007
JavaScript
MalwareHexEval Loader

HexEval Loader has executed malicious JavaScript code.

T1071.001
Web Protocols
MalwareHexEval Loader

HexEval Loader has used HTTP and HTTPS POST requests to communicate with C2.

T1082
System Information Discovery
MalwareHexEval Loader

HexEval Loader has identified the OS and MAC address of victim device through host fingerprinting scripting.

T1083
File and Directory Discovery
MalwareBeaverTail

BeaverTail has searched for .ldb and .log files stored in browser extension directories for collection and exfiltration.

T1105
Ingress Tool Transfer
MalwareBeaverTail

BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret.

T1105
Ingress Tool Transfer
MalwareHexEval Loader

HexEval Loader has been used to download a malicious payload to include BeaverTail.

T1140
Deobfuscate/Decode Files or Information
MalwareHexEval Loader

HexEval Loader has decoded its payload prior to execution.

T1204.005
Malicious Library
GroupContagious Interview

Contagious Interview has relied on users to install a malicious library from a code repository to infect the victim's device and has led to additional payload distribution and theft of sensitive data.

T1217
Browser Information Discovery
MalwareBeaverTail

BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets.

T1480
Execution Guardrails
GroupContagious Interview

Contagious Interview has configured C2 endpoints to review IP geolocation, request headers, victim environment details and runtime conditions prior to delivering payloads.

T1497
Virtualization/Sandbox Evasion
GroupContagious Interview

Contagious Interview has requested victims to disable Docker and other container environments in attempts to thwart container isolation and ensure device infection.

T1555.001
Keychain
GroupContagious Interview

Contagious Interview has leveraged malware variants configured to dump credentials from the macOS keychain.

T1555.001
Keychain
MalwareBeaverTail

BeaverTail has collected keys associated with macOS within `/Library/Keychains/login.keychain`.

T1555.003
Credentials from Web Browsers
MalwareBeaverTail

BeaverTail has stolen passwords saved in web browsers. BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from `/.mozilla/firefox/` for exfiltration.

T1583.001
Domains
GroupContagious Interview

Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2.

T1583.006
Web Services
GroupContagious Interview

Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities.

T1585
Establish Accounts
GroupContagious Interview

Contagious Interview has created and maintained personas on code repositories to distribute malicious payloads.

T1585.002
Email Accounts
GroupContagious Interview

Contagious Interview has created fake email accounts to correspond with social media accounts, fake LinkedIn personas, code repository accounts, and job announcements on development job board services. Contagious Interview has also utilized fake email accounts with Threat Intelligence vendor services.

T1587
Develop Capabilities
GroupContagious Interview

Contagious Interview developed malicious NPM packages for delivery to or retrieval by victims.

T1589
Gather Victim Identity Information
GroupContagious Interview

Contagious Interview has researched specific professional groups such as software developers for targeting. Contagious Interview has also researched individuals who work in roles related to cryptocurrency and blockchain technologies.

T1608.001
Upload Malware
GroupContagious Interview

Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download.

T1614
System Location Discovery
MalwareHexEval Loader

HexEval Loader has a function where the C2 endpoint can identify the geographical location of a victim host based on request headers, execution environment and runtime conditions.

T1657
Financial Theft
GroupContagious Interview

Contagious Interview has stolen cryptocurrency wallet credentials and credit card information utilizing BeaverTail and InvisibleFerret malware.

T1684.001
Impersonation
GroupContagious Interview

Contagious Interview had impersonated HR hiring personnel through social media, job board notifications, and conducted interviews with victims in order to entice them to download malware disguised as legitimate applications or malicious scripts from code repositories.

T1685
Disable or Modify Tools
GroupContagious Interview

Contagious Interview has convinced victims to disable Docker and other container environments and run code on their machine natively in attempts to bypass container isolation and ensure device infection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.