# Contagious Interview - G1052

> As of 2026-09-29, Contagious Interview - G1052 is a North Korea (DPRK)-nexus threat actor tracked by Threadlinqs Intelligence across 10 threats spanning malware, supply chain. Also known as DEV#POPPER, Contagious Interview cluster, DPRK-linked. ATT&CK coverage spans 96 techniques across 12 tactics in 10 of 10 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1082 (System Information Discovery), T1005 (Data from Local System).

- **Nation:** North Korea (DPRK)
- **Tracked threats:** 10
- **Categories:** MALWARE, SUPPLY_CHAIN
- **Also known as:** DEV#POPPER, Contagious Interview cluster, DPRK-linked
- **As of:** 2026-09-29

## ATT&CK techniques observed

96 techniques observed across 10 of 10 tracked threats. Tactics: Resource Development (14), Command and Control (13), Stealth (formerly Defense Evasion) (13), Collection (9), Credential Access (9), Discovery (9).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 9 of 10 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 9 of 10 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 8 of 10 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 8 of 10 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 8 of 10 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 7 of 10 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 7 of 10 tracked threats
- [T1070](https://intel.threadlinqs.com/technique/T1070) Indicator Removal — Stealth (formerly Defense Evasion) — observed in 6 of 10 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 6 of 10 tracked threats
- [T1115](https://intel.threadlinqs.com/technique/T1115) Clipboard Data — Collection — observed in 6 of 10 tracked threats
- [T1204](https://intel.threadlinqs.com/technique/T1204) User Execution — Execution — observed in 6 of 10 tracked threats
- [T1555](https://intel.threadlinqs.com/technique/T1555) Credentials from Password Stores — Credential Access — observed in 6 of 10 tracked threats
- [T1566](https://intel.threadlinqs.com/technique/T1566) Phishing — Initial Access — observed in 6 of 10 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 6 of 10 tracked threats
- [T1573](https://intel.threadlinqs.com/technique/T1573) Encrypted Channel — Command and Control — observed in 6 of 10 tracked threats

## Tracked threats

- [North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling](https://intel.threadlinqs.com/threat/TL-2026-2782) — HIGH
- [EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2](https://intel.threadlinqs.com/threat/TL-2026-2547) — HIGH
- [Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan](https://intel.threadlinqs.com/threat/TL-2026-1746) — CRITICAL
- [OTTERCOOKIE Malware Hidden in SVG Flag Images Backdoors Developers via Fake Coding Tests (Contagious Interview / REF9403)](https://intel.threadlinqs.com/threat/TL-2026-1581) — HIGH
- [ViteVenom: Blockchain-C2 npm Supply Chain Malware Targets Vite Ecosystem (Sequel to ChainVeil, PolinRider Cluster)](https://intel.threadlinqs.com/threat/TL-2026-1572) — HIGH
- [North Korean Contagious Interview Campaign Deploys OtterCookie via SVG Steganography to Steal Developer Credentials](https://intel.threadlinqs.com/threat/TL-2026-1571) — HIGH
- [Contagious Interview (DPRK) Uses SVG Steganography to Deliver OTTERCOOKIE/BEAVERTAIL Malware (REF9403)](https://intel.threadlinqs.com/threat/TL-2026-1450) — HIGH
- [North Korea-Linked Contagious Interview Actors (REF9403) Hide OtterCookie-Aligned Malware in SVG Flag Images](https://intel.threadlinqs.com/threat/TL-2026-1452) — HIGH
- [PolinRider DPRK npm Supply-Chain Loader Uses Blockchain Dead Drops for C2 (BeaverTail/InvisibleFerret)](https://intel.threadlinqs.com/threat/TL-2026-1215) — HIGH
- [PolinRider: North Korea-Linked Supply Chain Campaign Expands Across npm, Packagist, Go Modules, and Chrome Extensions](https://intel.threadlinqs.com/threat/TL-2026-1120) — CRITICAL

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052
