Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Contagious Interview

Also known as: DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, TAG-121, Famous Chollima, UNC5267, Wagemole, Nickel Tapestry, Storm-1877, Void Dokkaebi, WaterPlum

Description

Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrency-related activities. (Citation: Validin Contagious Interview North Korea ClickFix January 2025)(Citation: Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024)(Citation: Datadog Contagious Interview Tenacious Pungsan October 2024)(Citation: Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025)(Citation: ESET Contagious Interview BeaverTail InvisibleFerret February 2025)(Citation: Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024)(Citation: PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023)(Citation: PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024)

AI Analysis

· 1 week ago

Executive Summary

Contagious Interview is a North Korea-aligned threat group active since 2023, engaged in cyberespionage and financial theft targeting individuals in software development and cryptocurrency sectors. They employ sophisticated tactics including spearphishing and malware deployment, utilizing tools like BeaverTail for espionage activities.

Goals & Targeting

Contagious Interview's strategic objectives appear to be dual: conducting cyberespionage operations likely aimed at gathering sensitive information from the software development community and targeting cryptocurrency users and services for financial gain. Their focus on individuals engaged in software development suggests an interest in intellectual property theft, while their attention to cryptocurrency activities indicates a desire to exploit financial systems. Targeting countries where these sectors are prominent—such as South Korea, Japan, and other Asia-Pacific nations—aligns with North Korean state interests in both economic exploitation and intelligence gathering.

Enhanced Description

Contagious Interview operates as a state-sponsored cyber threat group linked to North Korea, leveraging both cyberespionage and financially motivated operations. The group's primary targets include individuals involved in software development and cryptocurrency-related activities across Windows, Linux, and macOS systems. They are known for deploying tools such as BeaverTail and InvisibleFerret, which enable them to conduct malicious activities including data theft and credential harvesting. Contagious Interview has demonstrated a high level of technical sophistication, employing advanced tactics to evade detection and persist in target environments.

Key Capabilities

  • Advanced persistent threat (APT) capabilities
  • Spearphishing campaigns
  • Malware development and deployment
  • Data exfiltration techniques
  • Credential harvesting
  • Cross-platform targeting (Windows, Linux, macOS)
  • Use of custom tools like BeaverTail and HexEval Loader

MITRE ATT&CK Tactics

Collection
Exfiltration
Defense Evasion
Credential Access
Discovery
Lateral Movement
Named Data
Endpoint
Network
Cloud
Evasion
Obfuscation

ATT&CK Techniques

T1566.003
T1583
T1059.007
T1573.001
T1036
T1587.001
T1204.002
T1583.001
T1083
T1204.005
T1583.006
T1059.004
T1571
T1683.002
T1059.006
T1059.003
T1027.010
T1070.004
T1048.003
T1588.007
T1027.013
T1555.001

Software / Tooling

InvisibleFerret
HexEval Loader
BeaverTail
XORIndex Loader

Campaigns & Victims

Contagious Interview has not been linked to specific, well-documented campaigns but is believed to be active in the Asia-Pacific region. Their targeting patterns suggest a focus on high-value individuals and organizations in software development and cryptocurrency sectors. While exact campaign details are sparse due to limited public reporting, their operational persistence and toolset evolution indicate continuous activity.

IOC Patterns

  • Spearphishing emails with malicious links or attachments
  • Malware deployment via email or targeted attacks
  • Network traffic indicative of data exfiltration
  • Use of encrypted channels for C2 communication
  • Presence of known malware tools like BeaverTail and HexEval Loader

Recommended Actions

  • Implement robust email filtering and phishing detection solutions.
  • Monitor for unauthorized access to system accounts and unusual network activity.
  • Conduct regular code reviews and implement software development security best practices.
  • Enhance endpoint protection with reputable EDR solutions capable of detecting advanced threats.
  • Educate employees on spotting spearphishing attempts and social engineering tactics.
  • Secure cryptocurrency assets with multi-factor authentication and isolated environments.

Suggested Tags

APT
Cyberespionage
Financial Theft
North Korea
Software Development
Cryptocurrency

Confidence Assessment

High confidence in Contagious Interview's North Korea affiliation and their use of specific malware tools. However, gaps exist in understanding the full scope of their operations, particularly regarding exact campaign details and victimology beyond initial intelligence.

ATT&CK Techniques

Command & Control
5 techniques
Execution
9 techniques
Exfiltration
4 techniques
Persistence
3 techniques
Reconnaissance
5 techniques
Resource Development
14 techniques
Stealth
7 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Sentinel One Contagious Interview ClickFix September 2025 — Aleksandar Milenkoski, Sreekar Madabushi, Kenneth Kinion. (2025, September 4). Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms. Retrieved October 20, 2025.
  2. Validin Contagious Interview North Korea ClickFix January 2025 — Efstratios Lontzetidis. (2025, January 16). Lazarus APT: Techniques for Hunting Contagious Interview. Retrieved October 20, 2025.
  3. Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024 — eSentire Threat Response Unit (TRU). (2024, November 14). Bored BeaverTail & InvisibleFerret Yacht Club – A Lazarus Lure Pt.2. Retrieved October 17, 2025.
  4. Datadog Contagious Interview Tenacious Pungsan October 2024 — Ian Kretz, Sebastian Obregoso, Datadog Security Research Team. (2024, October 24). Tenacious Pungsan: A DPRK threat actor linked to Contagious Interview. Retrieved October 20, 2025.
  5. Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025 — Insikt Group. (2025, February 13). Inside the Scam: North Korea’s IT Worker Threat. Retrieved October 17, 2025.
  6. ESET Contagious Interview BeaverTail InvisibleFerret February 2025 — Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.
  7. dtex DPRK 2025 structure ITworkers — Michael “Barni” Barnhart, DTEX, and Anonymous SMEs. (2025, May 14). Exposing DPRK's Cyber Syndicate and Hidden IT Workforce. Retrieved September 3, 2025.
  8. Securonix Contagious Interview DEVPOPPER April 2024 — Securonix Threat Research, D.Iuzvyk, T. Peck, O.Kolesnikov. (2024, April 24). Analysis of DEV#POPPER: New Attack Campaign Targeting Software Developers Likely Associated With North Korean Threat Actors. Retrieved October 20, 2025.
  9. Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 — Seongsu Park. (2024, November 4). From Pyongyang to Your Payroll: The Rise of North Korean Remote Workers in the West. Retrieved October 17, 2025.
  10. PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023 — Unit 42. (2023, November 21). Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors. Retrieved October 17, 2025.
  11. PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024 — Unit42. (2024, October 9). Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware. Retrieved October 17, 2025.

Intel Summary

54

Techniques

4

Tools

0

Campaigns

0

IOCs

0

Observed Data

13

Tactics

Tags

APT
Financial Targeting
Cyberespionage
Financial Theft
North Korea
Software Development
Cryptocurrency

Details

MITRE ID
G1052
Type
Unknown
Country of Origin
K
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--46599a4a-77ee-4697-9474-2683b6464859
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.