Contagious Interview

APT / StateG1052
Origin🇰🇵 Coreia do Norte
Techniques (MITRE ATT&CK)54
SourceMITRE ATT&CK
0
Also known as:DEV#POPPERDeceptiveDevelopmentGwisin GangPurpleBravoTAG-121Tenacious Pungsan

Vexday analysis

Alinhado à Coreia do Norte e ativo desde 2023, o Contagious Interview (também rastreado como DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo e TAG-121) conduz operações tanto de ciberespionagem quanto com motivação financeira, incluindo o roubo de criptomoedas e credenciais de usuários. O grupo tem como alvo sistemas Windows, Linux e macOS, com foco particular em indivíduos que atuam no desenvolvimento de software e em atividades relacionadas a criptomoedas. Ao grupo são atribuídas 54 técnicas documentadas no MITRE ATT&CK, sob o identificador G1052.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity60
Impact: High
T1566.003T1059.003T1543.001T1546.004T1082T1041ENTRYInitial accessSpearphishing viaServiceEXECExecutionWindows CommandShellPERSPersistenceLaunch AgentPRIVPrivilege escalationUnix ShellConfiguration Mod…DISCDiscoverySystem InformationDiscoveryEXFILExfiltrationExfiltration OverC2 ChannelIMPACTImpactFinancial Theft

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 26

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port95.216.64.240:1224InvisibleFerretthreatfox
ip:port95.217.102.138:1144InvisibleFerretthreatfox
ip:port138.201.128.169:1224InvisibleFerretthreatfox
urlhttp://144.172.103.226/301/301mInvisibleFerretthreatfox
urlhttp://144.172.103.226/301/301lInvisibleFerretthreatfox
urlhttp://144.172.103.226/301/301wInvisibleFerretthreatfox
urlhttp://95.217.102.138:1144/s/30620700InvisibleFerretthreatfox
urlhttp://95.216.64.240:1224/mainInvisibleFerretthreatfox
urlhttp://95.216.64.240:1224/client/36/700InvisibleFerretthreatfox
domainpub-acf013a9b65140b7b58cc3c104ee7105.r2.devInvisibleFerretthreatfox
domainpub-06714264305c44ea94491c0c8d961a87.r2.devInvisibleFerretthreatfox
sha256_hasha129de4fd4f1374a292bd8964df30c9e82c99bac680c4d36d6890fbf30ffac1cInvisibleFerretthreatfox
sha256_hash683a1607808f49446191d775d181ec9cccd1d629fba76e4d416fa54d1cf42630InvisibleFerretthreatfox
sha256_hashcd3b606d31c9d3c2ee972916f8de9a403caf00f00698fd6b9acece6ff30647c6InvisibleFerretthreatfox
sha256_hashb34aa84e8b4ad57d773fab6cbd7c40cda65f5f17c566cbd726ce3edcd04255b1InvisibleFerretthreatfox
sha256_hash02e6fbf7319629a352755bded9ec28dfdaffc0affb7c1a7de9a1b3b69bd91de5InvisibleFerretthreatfox
urlhttps://www.code-beautify.com/settings/packageBeaverTailurlhaus
urlhttps://www.code-beautify.com/settings/mac?flag=6BeaverTailurlhaus
urlhttps://www.code-beautify.com/settings/env?flag=6BeaverTailurlhaus
ip:port172.86.123.37:8086BeaverTailthreatfox
domaincode-beautify.comBeaverTailthreatfox
ip:port172.86.123.37:8087BeaverTailthreatfox
sha256_hash74009ad71c2f41ebfe6b76358f0224f814f8dca1167a858538b5e8df8a76b881BeaverTailthreatfox
domainipregionchecker.orgBeaverTailthreatfox
sha256_hash017cb09cabd9c909e4fb06e8c668d2f89e472e103eda5230d98761a9f998bdb5BeaverTailthreatfox
sha256_hash0e1ae44c555c13b03bdbd72f66c456aaffcdd13887ebe9859d302a63e409c462BeaverTailthreatfox

Contagious Interview uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →