Threadlinqs IntelligenceStart free

Threat actorNorth Korea (DPRK)Tracked since 2026-07

Contagious Interview - G1052

Also known as:DEV#POPPERContagious Interview clusterDPRK-linked

As of 2026-09-29, Contagious Interview - G1052 is a North Korea (DPRK)-nexus threat actor tracked by Threadlinqs Intelligence across 10 threats spanning malware, supply chain. Also known as DEV#POPPER, Contagious Interview cluster, DPRK-linked. ATT&CK coverage spans 96 techniques across 12 tactics in 10 of 10 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1082 (System Information Discovery), T1005 (Data from Local System).

Tracked threats
102 critical · 8 high
First seen
2026-07-01
Last seen
2026-09-29
ATT&CK techniques
96across 10 of 10 threats
Related CVEs
0None referenced
Attribution
North Korea (DPRK)Nation or origin
Nation: North Korea (DPRK) · 10 tracked threat(s) · Categories: MALWARE, SUPPLY_CHAIN

Activity timeline

Contagious Interview - G1052 appears in 10 tracked threats between and ; the busiest month was 2026-07 with 8 reports.

ATT&CK techniques observed

96 techniques observed across 10 of 10 tracked threats · Resource Development (14), Command and Control (13), Stealth (formerly Defense Evasion) (13), Collection (9), Credential Access (9), Discovery (9)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 9 of 10 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 9 of 10 tracked threats
  • T1005 Data from Local System — Collectionobserved in 8 of 10 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 8 of 10 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 8 of 10 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 7 of 10 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 7 of 10 tracked threats
  • T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 6 of 10 tracked threats
  • T1102 Web Service — Command and Controlobserved in 6 of 10 tracked threats
  • T1115 Clipboard Data — Collectionobserved in 6 of 10 tracked threats
  • T1204 User Execution — Executionobserved in 6 of 10 tracked threats
  • T1555 Credentials from Password Stores — Credential Accessobserved in 6 of 10 tracked threats
  • T1566 Phishing — Initial Accessobserved in 6 of 10 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 6 of 10 tracked threats
  • T1573 Encrypted Channel — Command and Controlobserved in 6 of 10 tracked threats

Tracked threats