T1027.010 Command Obfuscation |
GroupContagious Interview |
Contagious Interview has obfuscated JavaScript code using Base64 and variable substitutions. |
T1041 Exfiltration Over C2 Channel |
GroupContagious Interview |
Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers. |
T1204.002 Malicious File |
GroupContagious Interview |
Contagious Interview has distributed malicious files requiring direct victim interaction to execute through the guise of a code test. |
T1219.002 Remote Desktop Software |
GroupContagious Interview |
Contagious Interview has downloaded remote management and monitoring software such as “AnyDesk” for post compromise activities. |
T1566.003 Spearphishing via Service |
GroupContagious Interview |
Contagious Interview has used fake job advertisements and messages sent via social media to spearphish targets. Contagious Interview has also leveraged hiring websites to solicit victims. |
T1585.001 Social Media Accounts |
GroupContagious Interview |
Contagious Interview has created fake social media accounts such as LinkedIn and Telegram accounts for their targeting efforts. |
T1588.002 Tool |
GroupContagious Interview |
Contagious Interview has used remote management and monitoring software such as “AnyDesk”. |
T1589 Gather Victim Identity Information |
GroupContagious Interview |
Contagious Interview has researched specific professional groups such as software developers for targeting. Contagious Interview has also researched individuals who work in roles related to cryptocurrency and blockchain technologies. |
T1593.001 Social Media |
GroupContagious Interview |
Contagious Interview had identified and solicited victims through social media such as LinkedIn, X, and Telegram. |
T1608.001 Upload Malware |
GroupContagious Interview |
Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download. |
T1684.001 Impersonation |
GroupContagious Interview |
Contagious Interview had impersonated HR hiring personnel through social media, job board notifications, and conducted interviews with victims in order to entice them to download malware disguised as legitimate applications or malicious scripts from code repositories. |