FORENSIA

THREAT_ACTOR · G1052

Contagious Interview

Also known as: Contagious Interview, DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, TAG-121

Profile

Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrency-related activities.

MITRE ATT&CK ↗

Techniques

54 ATT&CK techniques attributed to this actor.

T1027.010 Command ObfuscationT1027.013 Encrypted/Encoded FileT1036 MasqueradingT1041 Exfiltration Over C2 ChannelT1048.003 Exfiltration Over Unencrypted Non-C2 ProtocolT1059.003 Windows Command ShellT1059.004 Unix ShellT1059.005 Visual BasicT1059.006 PythonT1059.007 JavaScriptT1070.004 File DeletionT1071.003 Mail ProtocolsT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1090 ProxyT1204.001 Malicious LinkT1204.002 Malicious FileT1204.004 Malicious Copy and PasteT1204.005 Malicious LibraryT1219.002 Remote Desktop SoftwareT1480 Execution GuardrailsT1497 Virtualization/Sandbox EvasionT1543.001 Launch AgentT1546.004 Unix Shell Configuration ModificationT1547.001 Registry Run Keys / Startup FolderT1547.013 XDG Autostart EntriesT1555.001 KeychainT1566.003 Spearphishing via ServiceT1567 Exfiltration Over Web ServiceT1567.002 Exfiltration to Cloud StorageT1571 Non-Standard PortT1573.001 Symmetric CryptographyT1583 Acquire InfrastructureT1583.001 DomainsT1583.003 Virtual Private ServerT1583.006 Web ServicesT1585 Establish AccountsT1585.001 Social Media AccountsT1585.002 Email AccountsT1587 Develop CapabilitiesT1587.001 MalwareT1588.002 ToolT1588.007 Artificial IntelligenceT1589 Gather Victim Identity InformationT1593 Search Open Websites/DomainsT1593.001 Social MediaT1593.003 Code RepositoriesT1608.001 Upload MalwareT1657 Financial TheftT1681 Search Threat Vendor DataT1683.001 Written ContentT1683.002 Audio-Visual ContentT1684.001 ImpersonationT1685 Disable or Modify Tools

Software

4 malware/tools attributed to this actor.

InvisibleFerretBeaverTailXORIndex LoaderHexEval Loader

Related corpus activity

10,321 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Contagious Interview.

IndicatorTypeFamilySevSrc
cve-2026-3102cve853
cve-2026-1969cve851
cve-2013-3307cve852
cve-2014-2321cve851
cve-2025-2492cve852
cve-2021-29441cve851
cve-2025-66478cve852
cve-2021-27076cve851
cve-2016-15047cve854
cve-2018-8007cve851
cve-2021-4045cve851
cve-2020-22658cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2016-5681cve852
cve-2022-47945cve851
cve-2025-0921cve852
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-68670cve852
cve-2025-34054cve854
cve-2024-1781cve851
cve-2025-23304cve852
cve-2023-44976cveransomware852
cve-2020-17456cve851
cve-2020-22653cve852
cve-2025-34117cve851
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,321.