Contagious Interview

APT / StateG1052 ↗
Origin🇰🇵 Coreia do Norte
Techniques (MITRE ATT&CK)54
SourceMITRE ATT&CK
0
Also known as:DEV#POPPERDeceptiveDevelopmentGwisin GangPurpleBravoTAG-121Tenacious Pungsan

About the group

Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrency-related activities.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity60
Impact: High
T1566.003T1059.003T1543.001T1546.004T1082T1041ENTRYInitial accessSpearphishing viaServiceEXECExecutionWindows CommandShellPERSPersistenceLaunch AgentPRIVPrivilege escalationUnix ShellConfiguration Mod…DISCDiscoverySystem InformationDiscoveryEXFILExfiltrationExfiltration OverC2 ChannelIMPACTImpactFinancial Theft

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 78

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

urlhttp://104.234.94.197:1244/mainBeaverTailurlhaus
urlhttp://104.234.94.197:1244/ncli/36/346BeaverTailurlhaus
urlhttp://104.234.94.197:1244/brow/36/346BeaverTailurlhaus
urlhttp://104.234.94.197:1244/payl/36/346BeaverTailurlhaus
urlhttp://104.234.94.197:1244/payload/36/346BeaverTailurlhaus
urlhttp://104.234.94.197:1244/ldb/36/346BeaverTailurlhaus
urlhttp://104.234.94.197:1244/client/36/346BeaverTailurlhaus
sha256_hash9a7c336c943bc92bf20bc698417653eb12a039f2a5b56bd1a12396ca99209b5bBeaverTailthreatfox
urlhttp://104.234.94.197:1244/payl/36/346BeaverTailthreatfox
urlhttp://104.234.94.197:1244/ncli/36/346BeaverTailthreatfox
urlhttp://104.234.94.197:2225/pd/lBeaverTailthreatfox
urlhttp://104.234.94.197:1244/mainBeaverTailthreatfox
urlhttp://104.234.94.197:1244/client/36/346BeaverTailthreatfox
urlhttp://104.234.94.197:1244/brow/36/346BeaverTailthreatfox
urlhttp://104.234.94.197:1244/payload/36/346BeaverTailthreatfox
urlhttp://104.234.94.197:1244/ldb/36/346BeaverTailthreatfox
ip:port104.234.94.197:1244BeaverTailthreatfox
ip:port104.234.94.197:2225BeaverTailthreatfox
ip:port138.201.124.236:1274BeaverTailthreatfox
ip:port91.121.235.123:1224BeaverTailthreatfox
urlhttps://ip-vm.vercel.app/api/settings/bootstrapBeaverTailthreatfox
urlhttps://ip-vm.vercel.app/api/settings/bootstraplinuxBeaverTailthreatfox
urlhttps://ip-vm.vercel.app/api/settings/packageBeaverTailthreatfox
urlhttps://ip-vm.vercel.app/api/settings/envBeaverTailthreatfox
urlhttps://ip-vm.vercel.app/api/settings/windowsBeaverTailthreatfox
urlhttps://ip-vm.vercel.app/api/settings/linuxBeaverTailthreatfox
urlhttps://ip-vm.vercel.app/api/settings/macBeaverTailthreatfox
ip:port51.210.52.212:1224BeaverTailthreatfox
urlhttp://51.210.52.212:1224/api/checkStatusBeaverTailthreatfox
urlhttps://gamboracle.vercel.app/apiBeaverTailthreatfox

+78 indicators in total. See them all on the IOCs page.

Contagious Interview uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →