T1041 Exfiltration Over C2 Channel |
GroupContagious Interview |
Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers. |
T1071.003 Mail Protocols |
GroupContagious Interview |
Contagious Interview has utilized email notifications from malware distribution servers to track victim engagement. |
T1204.004 Malicious Copy and Paste |
GroupContagious Interview |
Contagious Interview has leveraged ClickFix type tactics enticing victims to copy and paste malicious code. |
T1204.005 Malicious Library |
GroupContagious Interview |
Contagious Interview has relied on users to install a malicious library from a code repository to infect the victim's device and has led to additional payload distribution and theft of sensitive data. |
T1583 Acquire Infrastructure |
GroupContagious Interview |
Contagious Interview has used services such as Astrill VPN. |
T1583.001 Domains |
GroupContagious Interview |
Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2. |
T1583.006 Web Services |
GroupContagious Interview |
Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities. |
T1585 Establish Accounts |
GroupContagious Interview |
Contagious Interview has created and maintained personas on code repositories to distribute malicious payloads. |
T1585.002 Email Accounts |
GroupContagious Interview |
Contagious Interview has created fake email accounts to correspond with social media accounts, fake LinkedIn personas, code repository accounts, and job announcements on development job board services. Contagious Interview has also utilized fake email accounts with Threat Intelligence vendor services. |
T1587 Develop Capabilities |
GroupContagious Interview |
Contagious Interview developed malicious NPM packages for delivery to or retrieval by victims. |
T1589 Gather Victim Identity Information |
GroupContagious Interview |
Contagious Interview has researched specific professional groups such as software developers for targeting. Contagious Interview has also researched individuals who work in roles related to cryptocurrency and blockchain technologies. |
T1593 Search Open Websites/Domains |
GroupContagious Interview |
Contagious Interview has utilized open-source indicator of compromise repositories to determine their exposure to include VirusTotal, and MalTrail. |
T1608.001 Upload Malware |
GroupContagious Interview |
Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download. |
T1681 Search Threat Vendor Data |
GroupContagious Interview |
Contagious Interview has registered accounts with Threat Intelligence vendor services to check for reporting associated with their infrastructure and to evaluate new potential infrastructure. |
T1684.001 Impersonation |
GroupContagious Interview |
Contagious Interview had impersonated HR hiring personnel through social media, job board notifications, and conducted interviews with victims in order to entice them to download malware disguised as legitimate applications or malicious scripts from code repositories. |