Contagious Interview
Also tracked as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, TAG-121
Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrency-related activities.
- Documented techniques
- 54
- Assessed motivation
- Espionage, Financial gain
- First seen
- 2023
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
reconnaissance5
resource development14
- T1583 Acquire Infrastructure
- T1583.001 Domains
- T1583.003 Virtual Private Server
- T1583.006 Web Services
- T1585 Establish Accounts
- T1585.001 Social Media Accounts
- T1585.002 Email Accounts
- T1587 Develop Capabilities
- T1587.001 Malware
- T1588.002 Tool
- T1588.007 Artificial Intelligence
- T1608.001 Upload Malware
- T1683.001 Written Content
- T1683.002 Audio-Visual Content
initial access1
execution9
persistence3
privilege escalation1
credential access1
command and control5
exfiltration4
impact1
defense impairment1
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.