ATT&CKReferencesZscaler ContagiousInterview BeaverTail InvisibleFerret November 2024

Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024

Seongsu Park. (2024, November 4). From Pyongyang to Your Payroll: The Rise of North Korean Remote Workers in the West. Retrieved October 17, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples32

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
GroupContagious Interview

Contagious Interview has obfuscated JavaScript code using Base64 and variable substitutions.

T1027.013
Encrypted/Encoded File
MalwareBeaverTail

BeaverTail has obfuscated strings of code with Base64 encoding within the JavaScript version of the malware. BeaverTail has also utilized the open-source tool JavaScript-Obfuscator to obfuscate strings and functions.

T1036
Masquerading
GroupContagious Interview

Contagious Interview has delivered BeaverTail malware masquerading as legitimate software or applications. Contagious Interview has also delivered malicious payloads masquerading as legitimate software drivers.

T1041
Exfiltration Over C2 Channel
MalwareInvisibleFerret

InvisibleFerret has used HTTP communications to the “/Uploads” URI for file exfiltration.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareInvisibleFerret

InvisibleFerret has used FTP to exfiltrate files and directories using the command `ssh_upload` which contains with six subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr` and `sfind` that had varying functions. InvisibleFerret has exfiltrated stolen files and data to the C2 servers over ports 1224, 2245 and 8637.

T1056.001
Keylogging
MalwareInvisibleFerret

InvisibleFerret has conducted keylogging using the Python project “pyWinHook” and "Pyhook". InvisibleFerret has also captured keylogging thread checks for changes in an active window and key presses.

T1057
Process Discovery
MalwareInvisibleFerret

InvisibleFerret has the capability to query installed programs and running processes. InvisibleFerret has also identified running processes using the Python project “psutil”.

T1059.006
Python
MalwareInvisibleFerret

InvisibleFerret is written in Python and has used Python scripts for execution.

T1059.007
JavaScript
MalwareBeaverTail

BeaverTail has executed malicious JavaScript code. BeaverTail has also been compiled with the Qt framework to execute in both Windows and macOS.

T1083
File and Directory Discovery
MalwareInvisibleFerret

InvisibleFerret has identified specific directories and files for exfiltration using the `ssh_upload` command which contains subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr`, `sfind`. InvisibleFerret also has the capability to scan and upload files of interest from multiple OS systems through the use of scripts that check file names, file extensions, and avoids certain path names. InvisibleFerret has utilized the `findstr` on Windows or the macOS `find` commands to search for files of interest.

T1105
Ingress Tool Transfer
MalwareInvisibleFerret

InvisibleFerret has downloaded “AnyDesk.exe” into the user’s home directory from the C2 server when checks for the service fail to identify its presence in the victim environment. InvisibleFerret has also been configured to download additional payloads using a command which calls to the /bow URI.

T1115
Clipboard Data
MalwareInvisibleFerret

InvisibleFerret has stolen data from the clipboard using the Python project “pyperclip”. InvisibleFerret has also captured clipboard contents during copy and paste operations.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareBeaverTail

BeaverTail has been hosted on code repositories and disseminated to victims through NPM packages.

T1204.002
Malicious File
MalwareBeaverTail

BeaverTail has been executed through lures involving malicious JavaScript projects or trojanized remote conferencing software such as MicroTalk or FreeConference. BeaverTail has also been executed through macOS and Windows installers disguised as chat applications.

T1204.005
Malicious Library
GroupContagious Interview

Contagious Interview has relied on users to install a malicious library from a code repository to infect the victim's device and has led to additional payload distribution and theft of sensitive data.

T1219
Remote Access Tools
MalwareInvisibleFerret

InvisibleFerret has utilized remote access software including AnyDesk client through the “adc” module. InvisibleFerret has also downloaded the AnyDesk client should it not already exist on the compromised host by searching for `C:/Program Files(x86)/AnyDesk/AnyDesk.exe`.

T1518
Software Discovery
MalwareInvisibleFerret

InvisibleFerret has gathered installed programs and running processes.

T1543.001
Launch Agent
MalwareInvisibleFerret

InvisibleFerret has established persistence using LaunchAgents on macOS that run on Startup using a file named “com.avatar.update.wake.plist”.

T1543.001
Launch Agent
GroupContagious Interview

Contagious Interview has established persistence using InvisibleFerret malware to create file to run the script on Startup via LaunchAgents. Contagious Interview has also utilized a plist file located in `/Library/LaunchAgents` to enable a malicious bash script the ability to persist.

T1547.001
Registry Run Keys / Startup Folder
MalwareInvisibleFerret

InvisibleFerret has established persistence within Windows devices by creating a .bat file “queue.bat” within the Startup folder to run a Python script.

T1547.001
Registry Run Keys / Startup Folder
GroupContagious Interview

Contagious Interview has established persistence using InvisibleFerret malware to place a .bat file in the Startup Folder.

T1547.013
XDG Autostart Entries
GroupContagious Interview

Contagious Interview has established persistence using InvisibleFerret malware to create a .desktop entry to run on startup on GNOME-based Linux devices.

T1547.013
XDG Autostart Entries
MalwareInvisibleFerret

InvisibleFerret has established persistence within GNOME-based Linux environments by placing entries within `.desktop` that run on Startup.

T1555.003
Credentials from Web Browsers
MalwareInvisibleFerret

InvisibleFerret has stolen login data, autofill data, cryptocurrency wallets, and payment information saved in web browsers such as Chrome, Brave, Opera, Yandex and Edge, to include versions affiliated with major operating systems on Windows, Linux, and macOS. InvisibleFerret has also leveraged the command `ssh_zcp` to copy browser data to include extensions and cryptocurrency wallet data.

T1555.005
Password Managers
MalwareInvisibleFerret

InvisibleFerret has utilized the command `ssh_zcp` to exfiltrate data from browser extensions and password managers via Telegram and FTP.

T1560.001
Archive via Utility
MalwareInvisibleFerret

InvisibleFerret has used 7zip, RAR and zip files to archive collected data for exfiltration.

T1567
Exfiltration Over Web Service
MalwareInvisibleFerret

InvisibleFerret has leveraged Telegram chat to upload stolen data using the Telegram API with a bot token.

T1585.001
Social Media Accounts
GroupContagious Interview

Contagious Interview has created fake social media accounts such as LinkedIn and Telegram accounts for their targeting efforts.

T1585.002
Email Accounts
GroupContagious Interview

Contagious Interview has created fake email accounts to correspond with social media accounts, fake LinkedIn personas, code repository accounts, and job announcements on development job board services. Contagious Interview has also utilized fake email accounts with Threat Intelligence vendor services.

T1608.001
Upload Malware
GroupContagious Interview

Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download.

T1657
Financial Theft
GroupContagious Interview

Contagious Interview has stolen cryptocurrency wallet credentials and credit card information utilizing BeaverTail and InvisibleFerret malware.

T1657
Financial Theft
MalwareInvisibleFerret

InvisibleFerret has searched the victim device credentials and files commonly associated with cryptocurrency wallets.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.