Hacker groupG1052

Contagious Interview

Also tracked as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, TAG-121

Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrency-related activities.

Known attack methods
54
Motive
Espionage, Financial gain
First seen
2023
Source
MITRE ATT&CK

How they break in

Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.

Defense impairment1

Credential access1

Malware

Families MITRE records this group deploying. Detection names for these are a reasonable place to start.

BeaverTailHexEval LoaderInvisibleFerretXORIndex Loader