Intrusion setG1052

Contagious Interview

Also tracked as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, TAG-121

Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrency-related activities.

Documented techniques
54
Assessed motivation
Espionage, Financial gain
First seen
2023
Basis
MITRE ATT&CK

How they break in

Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.

credential access1

Malware

Families MITRE records this group deploying. Detection names for these are a reasonable place to start.

BeaverTailHexEval LoaderInvisibleFerretXORIndex Loader
Source: MITRE ATT&CK View the original record · Last synchronised 2026-09-09 · Origin and motivation are read from MITRE’s own description and are not structured fields in ATT&CK. Where the text does not attribute a group, this page leaves them blank rather than guessing.