Contagious Interview has obfuscated JavaScript code using Base64 and variable substitutions.9101112
group
Contagious Interview G1052
- Created
- 19 October 2025
- Last modified
- 31 July 2026
- Aliases
- Contagious Interview · DeceptiveDevelopment · Gwisin Gang · Tenacious Pungsan · DEV#POPPER · PurpleBravo · TAG-121
Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrency-related activities. [1][2][3][4][5][6][7][8]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G1052
Contagious Interview has used hexadecimal string encoding to hide critical JavaScript module names, function names, and C2 URLs, which are decoded dynamically at runtime.13
Contagious Interview has delivered BeaverTail malware masquerading as legitimate software or applications.1415161718 Contagious Interview has also delivered malicious payloads masquerading as legitimate software drivers.19
Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers.20212223242526272829
Contagious Interview has exfiltrated victim information using FTP.303132
Contagious Interview has utilized VBS scripts to open cmd.exe and run commands to include the go_batch.bat batch file.33
Standing G1052
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
86th percentile · 86% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
85th percentile · 85% of 176 ATT&CK groups have this many tactics spanned or fewer.
55th percentile · 55% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
11th percentile · 89% of 176 ATT&CK groups have more detection rules per technique.
Detection coverage G1052
938 distinct rules cover the 54 techniques recorded for this group. The 995 technique-to-rule mappings resolve to 938 distinct rules, because one rule can cover several techniques. 627 Sigma · 311 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org