Contagious Interview
MITREUnknown
Unknown
Unknown
[Contagious Interview](https://attack.mitre.org/groups/G1052) is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. [Contagious Interview](https://attack.mitre.org/groups/G1052) targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrency-related activities. (Citation: Validin Contagious Interview North Korea ClickFix January 2025)(Citation: Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024)(Citation: Datadog Contagious Interview Tenacious Pungsan October 2024)(Citation: Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025)(Citation: ESET Contagious Interview BeaverTail InvisibleFerret February 2025)(Citation: Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024)(Citation: PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023)(Citation: PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024)
Tecniche Utilizzate (52)
| ID | ATT&CK | Tattiche |
|---|---|---|
| T1027.010 | Command Obfuscation | - |
| T1027.013 | Encrypted/Encoded File | - |
| T1036 | Masquerading | - |
| T1041 | Exfiltration Over C2 Channel | - |
| T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol | - |
| T1059.003 | Windows Command Shell | - |
| T1059.004 | Unix Shell | - |
| T1059.005 | Visual Basic | - |
| T1059.006 | Python | - |
| T1059.007 | JavaScript | - |
| T1070.004 | File Deletion | - |
| T1071.003 | Mail Protocols | - |
| T1082 | System Information Discovery | - |
| T1083 | File and Directory Discovery | - |
| T1090 | Proxy | - |
Alias (624)
Malware Utilizzato (4)
Metadata
| ID: | 911 |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 04:00 |