ATT&CKReferencesSocket BeaverTail XORIndex HexEval Contagious Interview July 2025

Socket BeaverTail XORIndex HexEval Contagious Interview July 2025

Kirill Boychenko. (2025, July 14). Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader. Retrieved October 19, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples36

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareBeaverTail

BeaverTail has exfiltrated data collected from local systems.

T1016
System Network Configuration Discovery
MalwareXORIndex Loader

XORIndex Loader has leveraged webservices to identify the public IP of the victim host.

T1027.010
Command Obfuscation
MalwareXORIndex Loader

XORIndex Loader has obfuscated strings using ASCII buffers and TextDecoder.

T1027.013
Encrypted/Encoded File
MalwareXORIndex Loader

XORIndex Loader has encoded module names and C2 URLs as hexadecimal strings in attempts to evade analysis.

T1033
System Owner/User Discovery
MalwareXORIndex Loader

XORIndex Loader has collected the username from the victim host.

T1036.005
Match Legitimate Resource Name or Location
MalwareXORIndex Loader

XORIndex Loader has leveraged legitimate package names to mimic frequently utilized tools to entice victims to download and execute malicious payloads.

T1041
Exfiltration Over C2 Channel
MalwareBeaverTail

BeaverTail has exfiltrated data collected from victim devices to C2 servers.

T1041
Exfiltration Over C2 Channel
GroupContagious Interview

Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareXORIndex Loader

XORIndex Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers.

T1059.007
JavaScript
MalwareXORIndex Loader

XORIndex Loader has executed malicious JavaScript code.

T1070.004
File Deletion
MalwareBeaverTail

BeaverTail has deleted files from a compromised host after they were exfiltrated.

T1070.004
File Deletion
GroupContagious Interview

Contagious Interview has configured malware to remove archives used in collection activities following successful exfiltration.

T1071.001
Web Protocols
MalwareXORIndex Loader

XORIndex Loader has used HTTPS POST to communicate with C2.

T1071.001
Web Protocols
MalwareHexEval Loader

HexEval Loader has used HTTP and HTTPS POST requests to communicate with C2.

T1071.001
Web Protocols
MalwareBeaverTail

BeaverTail has used HTTP GET request to download malicious payloads to include InvisibleFerret and HTTP POST to exfiltrate data to C2 infrastructure.

T1074.001
Local Data Staging
MalwareBeaverTail

BeaverTail has staged collected data to the system’s temporary directory.

T1082
System Information Discovery
MalwareXORIndex Loader

XORIndex Loader has the ability to collect the hostname, OS Username, Geolocation, and OS version of an infected host.

T1083
File and Directory Discovery
MalwareBeaverTail

BeaverTail has searched for .ldb and .log files stored in browser extension directories for collection and exfiltration.

T1105
Ingress Tool Transfer
MalwareBeaverTail

BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret.

T1105
Ingress Tool Transfer
MalwareXORIndex Loader

XORIndex Loader has been used to download a malicious payload to include BeaverTail.

T1105
Ingress Tool Transfer
MalwareHexEval Loader

HexEval Loader has been used to download a malicious payload to include BeaverTail.

T1140
Deobfuscate/Decode Files or Information
MalwareHexEval Loader

HexEval Loader has decoded its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareXORIndex Loader

XORIndex Loader can decode its payload prior to execution.

T1204.005
Malicious Library
GroupContagious Interview

Contagious Interview has relied on users to install a malicious library from a code repository to infect the victim's device and has led to additional payload distribution and theft of sensitive data.

T1217
Browser Information Discovery
MalwareBeaverTail

BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets.

T1555.001
Keychain
MalwareBeaverTail

BeaverTail has collected keys associated with macOS within `/Library/Keychains/login.keychain`.

T1555.001
Keychain
GroupContagious Interview

Contagious Interview has leveraged malware variants configured to dump credentials from the macOS keychain.

T1555.003
Credentials from Web Browsers
MalwareBeaverTail

BeaverTail has stolen passwords saved in web browsers. BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from `/.mozilla/firefox/` for exfiltration.

T1560.001
Archive via Utility
MalwareBeaverTail

BeaverTail has collected and archived sensitive data in a zip file.

T1583.001
Domains
GroupContagious Interview

Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2.

T1583.006
Web Services
GroupContagious Interview

Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities.

T1585
Establish Accounts
GroupContagious Interview

Contagious Interview has created and maintained personas on code repositories to distribute malicious payloads.

T1587
Develop Capabilities
GroupContagious Interview

Contagious Interview developed malicious NPM packages for delivery to or retrieval by victims.

T1608.001
Upload Malware
GroupContagious Interview

Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download.

T1614
System Location Discovery
MalwareXORIndex Loader

XORIndex Loader can identify the geographical location of a victim host.

T1657
Financial Theft
GroupContagious Interview

Contagious Interview has stolen cryptocurrency wallet credentials and credit card information utilizing BeaverTail and InvisibleFerret malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.