G1052: Contagious Interview
Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrency-related activities. CitationValidin Contagious Interview North Korea ClickFix January 2025CitationEsentire ContagiousInterview BeaverTail InvisibleFerret November 2024CitationDatadog Contagious Interview Tenacious Pungsan October 2024CitationRecorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025CitationESET Contagious Interview BeaverTail InvisibleFerret February 2025CitationZscaler ContagiousInterview BeaverTail InvisibleFerret November 2024CitationPaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023CitationPaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024
Security context for executives and security teams
Contagious Interview matters because MITRE describes it as a North Korea-aligned group focused on software developers and cryptocurrency-related users, with reported credential and cryptocurrency theft. For leaders, the practical risk is not only malware on an endpoint; it is compromise of people who often hold source code access, package publishing rights, secrets, wallets, and privileged development credentials across Windows, Linux, and macOS environments.
Executive priority
Prioritize this as an identity, developer workstation, and data-loss risk. Ask whether the organization can prove control over developer endpoints, browser-stored credentials, script execution, package/library installation, remote desktop software, and outbound exfiltration paths. This object supports budget and audit discussions around developer security baselines, credential protection, SOC visibility across non-Windows systems, and incident response readiness for credential theft and exfiltration scenarios.
Technical view
MITRE provides no group-level detection text, so defenders should validate coverage through the related software and techniques. The relationship set points to user-driven execution through malicious links, files, copy/paste, and libraries; script and shell execution using Windows command shell, Unix shell, Visual Basic, Python, and JavaScript; obfuscation and masquerading; system and file discovery; command-and-control through mail protocols, proxies, and remote desktop software; and exfiltration over C2 or unencrypted non-C2 protocols. Related malware includes BeaverTail, InvisibleFerret, XORIndex Loader, and HexEval Loader, with Windows, Linux, and macOS relevance supported by the supplied descriptions.
Likely telemetry
- Endpoint process creation and command-line telemetry for cmd, Unix shells, Python, JavaScript runtimes, and Visual Basic execution
- Script content, interpreter invocation, and encoded or obfuscated command indicators where legally and operationally collectable
- File creation, deletion, rename, metadata, and masquerading evidence on developer workstations
- Browser credential store access indicators and suspicious access to local secrets or cryptocurrency-related files where monitored
- Network egress logs for C2-like traffic, mail protocol use, proxy behavior, remote desktop software sessions, and unencrypted outbound transfers
Detection direction
- Do not rely on a single malware signature; validate behavior-based detections across the related ATT&CK techniques and the named software families.
- Tune detections for developer environments where Python, JavaScript, shells, package managers, and remote tools are common, using context such as unusual parent processes, new destinations, encoded commands, and unexpected file access.
- Confirm SOC visibility on macOS and Linux developer systems, not only Windows, because the supplied descriptions and relationships include all three operating systems.
- Review detections for malicious copy/paste and user-assisted execution patterns, including commands pasted into shell or script interpreters after web or messaging activity.
- Correlate discovery, credential access indicators, downloader behavior, C2/proxy/remote desktop activity, and exfiltration telemetry rather than treating each as isolated low-severity noise.
Mitigation priorities
- Harden developer workstations first: least privilege, controlled script execution, endpoint protection, logging, and rapid isolation procedures for Windows, Linux, and macOS.
- Reduce credential theft impact by limiting browser-stored secrets, enforcing MFA where applicable, rotating exposed credentials during incidents, and separating developer, repository, cloud, and financial access.
- Strengthen software supply-chain hygiene by controlling package/library installation, reviewing dependencies, and monitoring developer package manager activity.
- Restrict and monitor remote desktop software and outbound proxy paths; require approved tools, documented business use, and centralized logging.
- Improve user-facing defenses for recruiting, interview, link, file, copy/paste, and library-install lures through targeted awareness and reporting paths for developers and cryptocurrency-related personnel.
Additional notes and limits
Aliases supplied for this group include Contagious Interview, DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, and TAG-121. The strongest local validation path is to map the related techniques and software to actual telemetry coverage for developer endpoints and identity systems, then test whether SOC workflows can connect user-assisted execution to credential theft and exfiltration risk.
The official object has no ATT&CK tactics, no object-level platforms field, and no official detection guidance. Platform and behavior discussion here is derived from the official description and supplied relationships. Local exposure depends on the organization’s developer population, cryptocurrency-related activity, endpoint mix, logging depth, and allowed remote access and package-management practices.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Contagious Interview
Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrency-related activities. CitationValidin Contagious Interview North Korea ClickFix January 2025CitationEsentire ContagiousInterview BeaverTail InvisibleFerret November 2024CitationDatadog Contagious Interview Tenacious Pungsan October 2024CitationRecorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025CitationESET Contagious Interview BeaverTail InvisibleFerret February 2025CitationZscaler ContagiousInterview BeaverTail InvisibleFerret November 2024CitationPaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023CitationPaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
