G1052

2025-10-19 • MITREContagious Interview

G1052, tracked by MITRE ATT&CK under the name Contagious Interview, is a North Korea-aligned threat group assessed to have been active since 2023, also associated in reporting with the names DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, and TAG-121. The group conducts both cyberespionage and financially motivated operations, including theft of cryptocurrency and credentials, targeting Windows, Linux, and macOS systems, with particular focus on software developers and individuals in cryptocurrency and blockchain roles. Its signature tactic is impersonating recruiters and hiring personnel via fake job advertisements and social-media outreach and interviews, luring victims to download malicious code disguised as coding tests, software, or drivers, often hosted on public code repositories or distributed via malicious package-manager packages. Malware families include a cross-platform tool built on Qt and a Python-based backdoor, used to steal cryptocurrency wallet credentials, credit card data, and browser and keychain credentials, and to establish persistence, alongside AI-generated content and fake-error-message prompts that trick victims into running malicious code.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster