created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false
Contagious Interview
Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G1052 |
| Aliases | DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, TAG-121 |
| Attribution | North Korea (curated: DPRK IT-worker campaign; alias cluster of Lazarus (G0032). ATT&CK describes the campaign without asserting the sponsor, and DPRK operations are financially motivated by design.) |
| Class | state |
| Active since | 2023 (per ATT&CK description) |
| ATT&CK entry created | 2025-10-19 |
| Techniques mapped | 58 |
Attribution — as claimed
Stated by MITRE ATT&CK (state attribution).
Known TTPs
| Technique | Name |
|---|---|
T1027.010 |
Command Obfuscation |
T1027.013 |
Encrypted/Encoded File |
T1036 |
Masquerading |
T1041 |
Exfiltration Over C2 Channel |
T1048.003 |
Exfiltration Over Unencrypted Non-C2 Protocol |
T1059.003 |
Windows Command Shell |
T1059.004 |
Unix Shell |
T1059.005 |
Visual Basic |
T1059.006 |
Python |
T1059.007 |
JavaScript |
T1070.004 |
File Deletion |
T1071.003 |
Mail Protocols |
(First 12 of 58 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Lazarus Group — North Korea-linked actor, same attribution class
- Apt38 — North Korea-linked actor, same attribution class
- Kimsuky — North Korea-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G1052 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.