Threadlinqs IntelligenceStart free

Threat actorNorth KoreaTracked since 2026-02

Contagious Interview

Also known as:Contagious Interview - G1052WageMoleFamous ChollimaDEV#POPPERDeceptiveDevelopmentGwisin GangPurpleBravoTAG-121Tenacious PungsanHexagonalRodentVoid DokkaebiBlueNoroff

As of 2026-09-29, Contagious Interview is a North Korea-nexus threat actor tracked by Threadlinqs Intelligence across 21 threats spanning malware, supply chain, apt. Also known as Contagious Interview - G1052, WageMole, Famous Chollima, DEV#POPPER. ATT&CK coverage spans 124 techniques across 13 tactics in 21 of 21 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1082 (System Information Discovery), T1105 (Ingress Tool Transfer).

Tracked threats
214 critical · 17 high
First seen
2026-02-24
Last seen
2026-09-29
ATT&CK techniques
124across 21 of 21 threats
Related CVEs
0None referenced
Attribution
North KoreaNation or origin
Nation: North Korea · 21 tracked threat(s) · Categories: MALWARE, SUPPLY_CHAIN, APT, PHISHING

Activity timeline

Contagious Interview appears in 21 tracked threats between and ; the busiest month was 2026-07 with 8 reports.

ATT&CK techniques observed

124 techniques observed across 21 of 21 tracked threats · Stealth (formerly Defense Evasion) (20), Resource Development (17), Command and Control (16), Credential Access (12), Persistence (12), Collection (11)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 18 of 21 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 18 of 21 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 18 of 21 tracked threats
  • T1005 Data from Local System — Collectionobserved in 16 of 21 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 15 of 21 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 15 of 21 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 14 of 21 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 14 of 21 tracked threats
  • T1204 User Execution — Executionobserved in 13 of 21 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 12 of 21 tracked threats
  • T1566 Phishing — Initial Accessobserved in 12 of 21 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 11 of 21 tracked threats
  • T1102 Web Service — Command and Controlobserved in 11 of 21 tracked threats
  • T1195 Supply Chain Compromise — Initial Accessobserved in 11 of 21 tracked threats
  • T1555 Credentials from Password Stores — Credential Accessobserved in 11 of 21 tracked threats

Tracked threats