Also known as: DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, TAG-121, Famous Chollima, UNC5267, Wagemole, Nickel Tapestry, Storm-1877, Void Dokkaebi, WaterPlum
Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrency-related activities. (Citation: Validin Contagious Interview North Korea ClickFix January 2025)(Citation: Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024)(Citation: Datadog Contagious Interview Tenacious Pungsan October 2024)(Citation: Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025)(Citation: ESET Contagious Interview BeaverTail InvisibleFerret February 2025)(Citation: Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024)(Citation: PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023)(Citation: PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024)
Executive Summary
Contagious Interview is a North Korea-aligned threat group active since 2023, engaged in cyberespionage and financial theft targeting individuals in software development and cryptocurrency sectors. They employ sophisticated tactics including spearphishing and malware deployment, utilizing tools like BeaverTail for espionage activities.
Goals & Targeting
Contagious Interview's strategic objectives appear to be dual: conducting cyberespionage operations likely aimed at gathering sensitive information from the software development community and targeting cryptocurrency users and services for financial gain. Their focus on individuals engaged in software development suggests an interest in intellectual property theft, while their attention to cryptocurrency activities indicates a desire to exploit financial systems. Targeting countries where these sectors are prominent—such as South Korea, Japan, and other Asia-Pacific nations—aligns with North Korean state interests in both economic exploitation and intelligence gathering.
Enhanced Description
Contagious Interview operates as a state-sponsored cyber threat group linked to North Korea, leveraging both cyberespionage and financially motivated operations. The group's primary targets include individuals involved in software development and cryptocurrency-related activities across Windows, Linux, and macOS systems. They are known for deploying tools such as BeaverTail and InvisibleFerret, which enable them to conduct malicious activities including data theft and credential harvesting. Contagious Interview has demonstrated a high level of technical sophistication, employing advanced tactics to evade detection and persist in target environments.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Contagious Interview has not been linked to specific, well-documented campaigns but is believed to be active in the Asia-Pacific region. Their targeting patterns suggest a focus on high-value individuals and organizations in software development and cryptocurrency sectors. While exact campaign details are sparse due to limited public reporting, their operational persistence and toolset evolution indicate continuous activity.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Contagious Interview's North Korea affiliation and their use of specific malware tools. However, gaps exist in understanding the full scope of their operations, particularly regarding exact campaign details and victimology beyond initial intelligence.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
54
Techniques
4
Tools
0
Campaigns
0
IOCs
0
Observed Data
13
Tactics