Contagious Interview
Also tracked as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, TAG-121
Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrency-related activities.
- Known attack methods
- 54
- Motive
- Espionage, Financial gain
- First seen
- 2023
- Source
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.
Reconnaissance
12 techniques · 3 used
Resource Development
9 techniques · 6 used
Initial Access
11 techniques · 1 used
Execution
20 techniques · 2 used
Persistence
22 techniques · 2 used
Privilege Escalation
13 techniques · 1 used
Stealth
30 techniques · 6 used
Defense Impairment
18 techniques · 1 used
Credential Access
17 techniques · 1 used
Discovery
34 techniques · 2 used
Lateral Movement
9 techniques
Collection
17 techniques
Command and Control
18 techniques · 5 used
Exfiltration
9 techniques · 3 used
Impact
15 techniques · 1 used
Reconnaissance5
Resource development14
- T1583Acquire Infrastructure
- T1583.001Domains
- T1583.003Virtual Private Server
- T1583.006Web Services
- T1585Establish Accounts
- T1585.001Social Media Accounts
- T1585.002Email Accounts
- T1587Develop Capabilities
- T1587.001Malware
- T1588.002Tool
- T1588.007Artificial Intelligence
- T1608.001Upload Malware
- T1683.001Written Content
- T1683.002Audio-Visual Content
Initial access1
Execution9
Persistence3
Privilege escalation1
Stealth7
Defense impairment1
Credential access1
Command and control5
Exfiltration4
Impact1
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.