Home · Wiki · Entities & Threat Actors
created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false

Contagious Interview

Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials.

Attribute Detail
ATT&CK ID G1052
Aliases DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, TAG-121
Attribution North Korea (curated: DPRK IT-worker campaign; alias cluster of Lazarus (G0032). ATT&CK describes the campaign without asserting the sponsor, and DPRK operations are financially motivated by design.)
Class state
Active since 2023 (per ATT&CK description)
ATT&CK entry created 2025-10-19
Techniques mapped 58

Attribution — as claimed

Stated by MITRE ATT&CK (state attribution).

Known TTPs

Technique Name
T1027.010 Command Obfuscation
T1027.013 Encrypted/Encoded File
T1036 Masquerading
T1041 Exfiltration Over C2 Channel
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
T1059.003 Windows Command Shell
T1059.004 Unix Shell
T1059.005 Visual Basic
T1059.006 Python
T1059.007 JavaScript
T1070.004 File Deletion
T1071.003 Mail Protocols

(First 12 of 58 ATT&CK-mapped techniques.)

Related Pages

  • Mitre Attack — the framework this page's data is drawn from
  • Lazarus Group — North Korea-linked actor, same attribution class
  • Apt38 — North Korea-linked actor, same attribution class
  • Kimsuky — North Korea-linked actor, same attribution class

Provenance

Stub generated from MITRE ATT&CK G1052 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.