Contagious Interview

MITRE ATT&CK: G1052 View on attack.mitre.org

Aliases: DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, TAG-121, Contagious Interview

First seen
2023-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-07-21 16:30:27
Profile updated
2026-07-07 12:19:03

Targeted industries: financial-services technology-and-telecommunications professional-services

Context

Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrency-related activities.

Detection coverage

  • 1 YARA rules
  • 555 Sigma rules

Malware & tools used

  • Keychain (attack-pattern)
  • Establish Accounts (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Web Services (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Malicious Library (attack-pattern)
  • Remote Desktop Software (attack-pattern)
  • Masquerading (attack-pattern)
  • Malicious File (attack-pattern)
  • Virtualization/Sandbox Evasion (attack-pattern)
  • Exfiltration Over Web Service (attack-pattern)
  • Unix Shell (attack-pattern)
  • Malware (attack-pattern)
  • Code Repositories (attack-pattern)
  • Domains (attack-pattern)
  • Spearphishing via Service (attack-pattern)
  • Unix Shell Configuration Modification (attack-pattern)
  • Written Content (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Search Threat Vendor Data (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Financial Theft (attack-pattern)
  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
  • JavaScript (attack-pattern)
  • XDG Autostart Entries (attack-pattern)

Reports & references

  • Palo Alto Unit 42 — Two Campaigns By North Korea Bad Actors Target Job Hunters (report)
  • zscaler.com — Pyongyang Your Payroll Rise North Korean Remote Workers West (report)
  • about.gitlab.com — Gitlab Threat Intelligence Reveals North Korean Tradecraft (report)
  • sentinelone.com — Contagious Interview Threat Actors Scout Cyber Intel Platforms Reveal Plans And Ops (report)
  • Microsoft — Contagious Interview Malware Delivered Through Fake Developer Job Interviews (report)
  • MITRE ATT&CK — G1052 (report)
  • reports.dtexsystems.com — Dtex Exposing+Dprk+Cyber+Syndicate+And+Hidden+It+Workforce (report)
  • securitylabs.datadoghq.com — Tenacious Pungsan Dprk Threat Actor Contagious Interview (report)
  • Palo Alto Unit 42 — North Korean Threat Actors Lure Tech Job Seekers As Fake Recruiters (report)
  • esentire.com — Bored Beavertail Invisibleferret Yacht Club A Lazarus Lure Pt 2 (report)
  • recordedfuture.com — Inside The Scam North Koreas It Worker Threat (report)
  • securonix.com — Analysis Of Devpopper New Attack Campaign Targeting Software Developers Likely Associated With North Korean Threat Actors (report)
  • validin.com — Inoculating Contagious Interview With Validin (report)
  • ESET — Deceptivedevelopment Targets Freelance Developers (report)

Attributed from

  • Contagious Interview (campaign)

External references