T1027.010 Command Obfuscation |
GroupContagious Interview |
Contagious Interview has obfuscated JavaScript code using Base64 and variable substitutions. |
T1027.013 Encrypted/Encoded File |
GroupContagious Interview |
Contagious Interview has used hexadecimal string encoding to hide critical JavaScript module names, function names, and C2 URLs, which are decoded dynamically at runtime. |
T1036 Masquerading |
GroupContagious Interview |
Contagious Interview has delivered BeaverTail malware masquerading as legitimate software or applications. Contagious Interview has also delivered malicious payloads masquerading as legitimate software drivers. |
T1041 Exfiltration Over C2 Channel |
GroupContagious Interview |
Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers. |
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupContagious Interview |
Contagious Interview has exfiltrated victim information using FTP. |
T1059.003 Windows Command Shell |
GroupContagious Interview |
Contagious Interview has utilized VBS scripts to open cmd.exe and run commands to include the go_batch.bat batch file. |
T1059.004 Unix Shell |
GroupContagious Interview |
Contagious Interview has targeted macOS victim hosts using a bash downloader coremedia.sh and a bash script cloud.sh. |
T1059.005 Visual Basic |
GroupContagious Interview |
Contagious Interview has utilized Visual Basic scripts in the execution of their downloader malware targeting Windows devices including as script called update.vbs. |
T1059.006 Python |
GroupContagious Interview |
Contagious Interview has used the Python-based malware such as InvisibleFerret to install and execute Python Packages and Python modules. |
T1059.007 JavaScript |
GroupContagious Interview |
Contagious Interview has leveraged JavaScript in the execution of their downloader malware targeting Windows devices using a NodeJS script titled nvidia.js. |
T1070.004 File Deletion |
GroupContagious Interview |
Contagious Interview has configured malware to remove archives used in collection activities following successful exfiltration. |
T1071.003 Mail Protocols |
GroupContagious Interview |
Contagious Interview has utilized email notifications from malware distribution servers to track victim engagement. |
T1082 System Information Discovery |
GroupContagious Interview |
Contagious Interview has configured malicious webpages to identify the victim’s operating system by reviewing the details of the victims User-Agent of their browser. |
T1083 File and Directory Discovery |
GroupContagious Interview |
Contagious Interview has conducted key word searches within files and directories on a compromised hosts to identify files for exfiltration. |
T1090 Proxy |
GroupContagious Interview |
Contagious Interview has leveraged Astrill VPN for C2. |
T1204.001 Malicious Link |
GroupContagious Interview |
Contagious Interview has lured victims to click on a malicious link that led to download of a malicious payload. Contagious Interview has also leveraged links to malicious payloads on social media and code repositories. |
T1204.002 Malicious File |
GroupContagious Interview |
Contagious Interview has distributed malicious files requiring direct victim interaction to execute through the guise of a code test. |
T1204.004 Malicious Copy and Paste |
GroupContagious Interview |
Contagious Interview has leveraged ClickFix type tactics enticing victims to copy and paste malicious code. |
T1204.005 Malicious Library |
GroupContagious Interview |
Contagious Interview has relied on users to install a malicious library from a code repository to infect the victim's device and has led to additional payload distribution and theft of sensitive data. |
T1219.002 Remote Desktop Software |
GroupContagious Interview |
Contagious Interview has downloaded remote management and monitoring software such as “AnyDesk” for post compromise activities. |
T1480 Execution Guardrails |
GroupContagious Interview |
Contagious Interview has configured C2 endpoints to review IP geolocation, request headers, victim environment details and runtime conditions prior to delivering payloads. |
T1497 Virtualization/Sandbox Evasion |
GroupContagious Interview |
Contagious Interview has requested victims to disable Docker and other container environments in attempts to thwart container isolation and ensure device infection. |
T1543.001 Launch Agent |
GroupContagious Interview |
Contagious Interview has established persistence using InvisibleFerret malware to create file to run the script on Startup via LaunchAgents. Contagious Interview has also utilized a plist file located in `/Library/LaunchAgents` to enable a malicious bash script the ability to persist. |
T1546.004 Unix Shell Configuration Modification |
GroupContagious Interview |
Contagious Interview has targeted macOS victim hosts using a bash downloader `coremedia.sh` and a bash script `cloud.sh`. |
T1547.001 Registry Run Keys / Startup Folder |
GroupContagious Interview |
Contagious Interview has established persistence using InvisibleFerret malware to place a .bat file in the Startup Folder. |
T1547.013 XDG Autostart Entries |
GroupContagious Interview |
Contagious Interview has established persistence using InvisibleFerret malware to create a .desktop entry to run on startup on GNOME-based Linux devices. |
T1555.001 Keychain |
GroupContagious Interview |
Contagious Interview has leveraged malware variants configured to dump credentials from the macOS keychain. |
T1566.003 Spearphishing via Service |
GroupContagious Interview |
Contagious Interview has used fake job advertisements and messages sent via social media to spearphish targets. Contagious Interview has also leveraged hiring websites to solicit victims. |
T1567 Exfiltration Over Web Service |
GroupContagious Interview |
Contagious Interview has leveraged Telegram API to exfiltrate stolen data. |
T1567.002 Exfiltration to Cloud Storage |
GroupContagious Interview |
Contagious Interview has exfiltrated stolen passwords to Dropbox. |
T1571 Non-Standard Port |
GroupContagious Interview |
Contagious Interview has used TCP port 1224 for C2. |
T1573.001 Symmetric Cryptography |
GroupContagious Interview |
Contagious Interview has encrypted C2 traffic using RC4. |
T1583 Acquire Infrastructure |
GroupContagious Interview |
Contagious Interview has used services such as Astrill VPN. |
T1583.001 Domains |
GroupContagious Interview |
Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2. |
T1583.003 Virtual Private Server |
GroupContagious Interview |
Contagious Interview has acquired virtual private servers from services such as Stark Industries Solutions and RouterHosting. Contagious Interview has also utilized hosting providers to include Tier[.]Net, Majestic Hosting, Leaseweb Singapore, and Kaopu Cloud. |
T1583.006 Web Services |
GroupContagious Interview |
Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities. |
T1585 Establish Accounts |
GroupContagious Interview |
Contagious Interview has created and maintained personas on code repositories to distribute malicious payloads. |
T1585.001 Social Media Accounts |
GroupContagious Interview |
Contagious Interview has created fake social media accounts such as LinkedIn and Telegram accounts for their targeting efforts. |
T1585.002 Email Accounts |
GroupContagious Interview |
Contagious Interview has created fake email accounts to correspond with social media accounts, fake LinkedIn personas, code repository accounts, and job announcements on development job board services. Contagious Interview has also utilized fake email accounts with Threat Intelligence vendor services. |
T1587 Develop Capabilities |
GroupContagious Interview |
Contagious Interview developed malicious NPM packages for delivery to or retrieval by victims. |
T1587.001 Malware |
GroupContagious Interview |
Contagious Interview has developed malware that utilizes Qt cross-platform framework to include BeaverTail. |
T1588.002 Tool |
GroupContagious Interview |
Contagious Interview has used remote management and monitoring software such as “AnyDesk”. |
T1588.007 Artificial Intelligence |
GroupContagious Interview |
Contagious Interview has appeared to have used AI to generate images and content to facilitate their campaigns. |
T1589 Gather Victim Identity Information |
GroupContagious Interview |
Contagious Interview has researched specific professional groups such as software developers for targeting. Contagious Interview has also researched individuals who work in roles related to cryptocurrency and blockchain technologies. |
T1593 Search Open Websites/Domains |
GroupContagious Interview |
Contagious Interview has utilized open-source indicator of compromise repositories to determine their exposure to include VirusTotal, and MalTrail. |
T1593.001 Social Media |
GroupContagious Interview |
Contagious Interview had identified and solicited victims through social media such as LinkedIn, X, and Telegram. |
T1593.003 Code Repositories |
GroupContagious Interview |
Contagious Interview had identified and solicited victims through code repositories such as GitHub. |
T1608.001 Upload Malware |
GroupContagious Interview |
Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download. |
T1657 Financial Theft |
GroupContagious Interview |
Contagious Interview has stolen cryptocurrency wallet credentials and credit card information utilizing BeaverTail and InvisibleFerret malware. |
T1681 Search Threat Vendor Data |
GroupContagious Interview |
Contagious Interview has registered accounts with Threat Intelligence vendor services to check for reporting associated with their infrastructure and to evaluate new potential infrastructure. |