Home/Threat Actor/Contagious Interview
Threat Actor

Contagious Interview

contagious_interview · north_korea · active since 2022

Contagious Interview (Famous Chollima / DeceptiveDevelopment / DEV#POPPER / CL-STA-0240 / UNC5342 / Void Dokkaebi / PurpleBravo / TAG-120 / G1052) is a DPRK state-aligned cyber-threat cluster operating under the Reconnaissance General Bureau, active since at least 2022 and first publicly documented by Palo Alto Networks Unit 42 in November 2023.

the cluster represents a defining DPRK operational innovation, weaponized fake-job- interview tradecraft targeting software developers (particularly in cryptocurrency, Web3, blockchain, and AI sectors) via cross-platform malware delivered through trojanized 'coding challenge' repositories and NPM packages, operationally paired with the parallel Wagemole IT-worker fraud scheme (Contagious Interview targets developers as victims, Wagemole targets employers as victims)

mission profile blends cryptocurrency theft (the BeaverTail Qt variant targets 13 cryptocurrency wallet browser extensions including MetaMask, Phantom, and TrustWallet) with software-supply-chain access (CI/CD pipeline compromise, signing-key theft, code-repository access); tradecraft hallmarks include high-touch recruiter persona development on LinkedIn / Discord / Fiverr / Upwork / Telegram / GitHub / GitLab / Bitbucket / major job boards, AI-generated employee photos and front-company personas (Silent Push BlockNovas investigation documented Remaker AI use, first publicly-documented case of DPRK state-aligned AI-generated persona development at operational scale), Astrill VPN and residential proxies for infrastructure obfuscation, the BeaverTail JavaScript info-stealer + loader / InvisibleFerret Python cross-platform backdoor / OtterCookie December 2024 backdoor with Socket.IO C2 / FROSTYFERRET and GolangGhost RAT in ClickFake Interview variants (Sekoia April 2025) / Visual Studio Code workspace-task abuse (Trend Micro late 2025, automatic execution when victims accept trust prompts) / MetaMask extension surgical replacement with forged HMAC-SHA256 signatures / heavy code obfuscation via Obfuscator.io / AnyDesk remote-access tool post-compromise.

March 2026 Microsoft comprehensive analysis and ongoing FAMOUS CHOLLIMA CrowdStrike tracking demonstrate sustained operational tempo.

north_korea confidence: high 34 aliases MITRE ATT&CK G1052 ↗

Profile

Contagious Interview (Famous Chollima / DeceptiveDevelopment / DEV#POPPER / CL-STA-0240 / UNC5342 / Void Dokkaebi / PurpleBravo / TAG-120 / Tenacious Pungsan / ClickFake Interview / G1052) is a Democratic People's Republic of Korea (DPRK) state-aligned cyber threat cluster operating under the Reconnaissance General Bureau (RGB). Active since at least 2022 (first publicly documented by Palo Alto Networks Unit 42 in November 2023), Contagious Interview represents a defining DPRK operational innovation: weaponized fake-job-interview tradecraft targeting software developers, particularly in cryptocurrency, Web3, blockchain, and AI sectors, via cross-platform malware delivered through trojanized 'coding challenge' repositories and NPM packages. Contagious Interview is operationally paired with the parallel Wagemole IT-worker fraud scheme: Contagious Interview targets developers as victims (delivering BeaverTail / InvisibleFerret / OtterCookie to job seekers), while Wagemole targets employers as victims (DPRK nationals using AI-generated personas to gain remote employment at Western companies for sustained insider access plus salary remittance to the DPRK regime). Together, the two schemes form a unified DPRK strategy for compromising the global software-development workforce at scale. The mission profile blends financial theft (the dominant driver, cryptocurrency wallet credential and seed-phrase theft from MetaMask, Phantom, TrustWallet, and 10+ other crypto browser extensions.

the BeaverTail Qt variant targets 13 cryptocurrency wallet browser extensions) with software- supply-chain access (CI/CD pipeline compromise, signing-key theft, code-repository access, downstream propagation when compromised packages reach organizational or open-source repositories). The Recorded Future PurpleBravo tracking documented targeting of three cryptocurrency-space organizations October-November 2024, a market-making company, an online casino, and a software development company. The Silent Push BlockNovas investigation documented AI-generated employee personas at scale (Remaker AI / remaker[.]ai for synthetic profile photos), the first publicly-documented case of DPRK state-aligned AI-generated persona development at operational scale. Tradecraft hallmarks distinguish Contagious Interview from other DPRK clusters (APT37, APT38, Andariel, Kimsuky): (a) high-touch recruiter persona development on LinkedIn, Discord, Fiverr, Upwork, Telegram, GitHub, GitLab, Bitbucket, and major job boards; (b) AI-generated employee photos and front-company personas (Silent Push BlockNovas documentation); (c) Astrill VPN and residential proxies for operational- infrastructure obfuscation; (d) BeaverTail JavaScript info-stealer + loader as initial payload, delivered via trojanized NPM packages, Node.js applications (e.g., 'Chessfi' Web3 chess app), or Qt-compiled executables masquerading as conferencing applications; (e) InvisibleFerret Python cross-platform (Windows/Linux/macOS) backdoor as follow-on payload; (f) OtterCookie (December 2024+) as additional/alternative backdoor with Socket.IO C2, clipboard monitoring, and screenshot capabilities; (g) FROSTYFERRET and GolangGhost RAT in ClickFake Interview variants (Sekoia April 2025) using ClickFix-style 'browser needs to update' pretexts during video assessments; (h) Visual Studio Code workspace-task abuse (Trend Micro late 2025), workspace task configuration files execute automatically when victims accept trust prompts; (i) heavy code obfuscation via Obfuscator.io, XOR-based string encryption, and shuffled base64 C2 addresses; (j) MetaMask extension surgical replacement with forged HMAC-SHA256 signatures (preserving legitimate functionality); (k) AnyDesk remote-access tool deployment post-compromise; (l) high operational tempo with rapid sample iteration defeating VirusTotal-based detection reliability. The campaign represents both a major financial-cyber operation (funding the DPRK regime through crypto theft) and a strategic software-supply-chain risk (potential downstream propagation via compromised repositories), combining DPRK's traditional financial-cyber-revenue focus with an emerging supply-chain capability. The March 2026 Microsoft comprehensive analysis and ongoing FAMOUS CHOLLIMA CrowdStrike tracking demonstrate sustained 2026 operational tempo.

Aliases

34
contagious interviewcontagiousinterviewfamous chollimafamouschollimadeceptivedevelopmentdeceptive developmentdev#popperdev_popperdevpoppercl-sta-0240cl_sta_0240cl-sta-240unc5342unc 5342void dokkaebivoid_dokkaebipurplebravopurple bravotag-120tag_120tenacious pungsantenacious_pungsanclickfake interviewclickfake_interviewblocknovasblock novaswagemolewage molepurpledeltapurple deltargbreconnaissance general bureaudprkg1052

MITRE ATT&CK aliases

2
Additional names MITRE lists for G1052.
Gwisin GangTAG-121

Notable Campaigns

10
2026Microsoft Contagious Interview Comprehensive Analysis (March 11, 2026)
2026Python GolangGhost RAT Deployment (2026)
2025-2026Visual Studio Code Workspace Task Abuse (Trend Micro Late 2025)
2025ClickFake Interview Sekoia Disclosure (April 2025)
2025Recorded Future PurpleBravo Tracking (February 2025)
2024-2025BlockNovas and Related Front-Company Infrastructure (Silent Push 2024-2025)
2024-2025FAMOUS CHOLLIMA Scaling Insider-Risk Operations (CrowdStrike 2024-2025)
2024BeaverTail Qt Framework Pivot (Unit 42 October 2024)
2024OtterCookie Backdoor Discovery (December 2024)
2023Unit 42 Initial Contagious Interview Disclosure (November 2023)

Attribution & Reporting

Attributed by
FBICISANSAUS Cyber CommandUS Department of JusticeUS Department of TreasuryUS Department of Treasury OFACUS Department of StateUK NCSCRepublic of Korea NISRepublic of Korea KISAFive EyesMicrosoftMicrosoft Threat Intelligence Center (MSTIC)Microsoft Defender Security ResearchMandiantGoogle Cloud Threat IntelligenceGoogle Threat Analysis GroupCrowdStrikePalo Alto Networks Unit 42Trend MicroTrend Micro ResearchCisco TalosKaspersky GReATRecorded FutureInsikt GroupSentinelOneSentinelLabsSymantec / BroadcomESETSekoiaSecuronixVolexitySilent PushSecurityScorecardHuntressOktaSANS InstituteGitHub SecurityGitGuardian
Key reporting
reportPalo Alto Networks Unit 42: Contagious Interview Initial Disclosure (November 2023)
reportPalo Alto Networks Unit 42: DPRK Threat Actors Lure Tech Industry Job Seekers, Unit 42 New BeaverTail Variants (October 17, 2024)
reportPalo Alto Networks Unit 42: DPRK Malware-as-a-Service Contagious Interview (multiple)
reportMicrosoft Defender Security Research: Contagious Interview, Malware Delivered Through Fake Developer Job Interviews (March 11, 2026)
reportMicrosoft Threat Intelligence: Famous Chollima Deploying Python Version of GolangGhost RAT (2026)
reportMandiant: Contagious Interview DPRK IT Workers (multiple, 2024-2026)
reportCrowdStrike: FAMOUS CHOLLIMA Adversary Profile and Insider-Risk Reporting (multiple, 2024-2025)
reportRecorded Future / Insikt Group: Inside the Scam, North Korea's IT Worker Threat (February 2025)
reportRecorded Future / Insikt Group: PurpleBravo Tracking (formerly TAG-120)
reportSilent Push: Contagious Interview Front Companies, BlockNovas (December 2024 - 2025)
reportCisco Talos: Famous Chollima BeaverTail / OtterCookie / Chessfi Node.js Analysis (October 2025)
reportTrend Micro: Void Dokkaebi VS Code Workspace Task Abuse (Late 2025 - 2026)
reportESET: DeceptiveDevelopment DPRK Job Seekers
reportSekoia: ClickFake Interview DPRK Contagious Interview (April 2025)
reportSecuronix: DEV#POPPER DPRK Job-Fakes Security Advisory
reportSOCRadar: Famous Chollima aka Contagious Interview Profile
reportSecurityScorecard: The Job Offer That Wasn't, How We Stopped an Espionage Plot (October 2024)
reportUS Treasury OFAC JY-1938: Kimsuky Designation (November 2023), Wagemole-related context
reportFBI Advisories: IT Worker Threat and Wagemole-Related Activity (multiple)
reportUS DOJ Indictments: DPRK IT-Worker Insider Threat Indictments (multiple, 2024-2025)
reportCouncil on Foreign Relations: Famous Chollima Cyber Operations Tracker
reportEuRepoC: APT Profile, Famous Chollima

Operational

State sponsor

Democratic People's Republic of Korea (DPRK), Reconnaissance General Bureau (RGB). Tracked by Mandiant, Microsoft, Unit 42, CrowdStrike, Recorded Future, Trend Micro, Cisco Talos, and others as a distinct DPRK-aligned cluster operating in parallel with the Wagemole IT-worker scheme. Some vendors (e.g., Silent Push) characterize Contagious Interview as a subgroup of the broader Lazarus umbrella.

other vendors treat it as a separately-tracked cluster. CrowdStrike's FAMOUS CHOLLIMA designation specifically encompasses the recruitment-driven access operations. Mission: cryptocurrency theft and supply-chain access via fake-recruiter-and-coding-challenge social engineering.

Motivations
financial_theft, cryptocurrency_theft, cryptocurrency_wallet_theft, regime_funding, sanctions_evasion, software_supply_chain_compromise, developer_credential_theft, source_code_theft, ci_cd_pipeline_compromise, signing_key_theft, intellectual_property_theft, espionage_secondary
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)55/60 · 91%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)5/60 · 8%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)13/60 · 21%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

8 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
METAMASK EXTENSION REPLACEMENTMETERPRETER

CVEs Exploited

2
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin