---
title: "Threat Intel Content Update: 11/19/2025"
description: Tidal Cyber's Threat Intelligence Content updates for the week of 11/19/25 - Contagious Interview
---

[Threat Intelligence Content Updates ](https://www.tidalcyber.com/threat-updates)

# [Threat Intel Content Update: 11/19/2025](https://www.tidalcyber.com/threat-updates/threat-intel-content-update-11/19/2025)

 Written by [Tidal Cyber](https://www.tidalcyber.com/threat-updates/author/tidal-cyber) | Nov 20, 2025 2:00:02 PM

#### **"Contagious Interview” Behavior Evolution**

This week’s update continues to highlight our AI adversary & behavior extraction capabilities while also reminding of our regular “extensions” of the formal ATT&CK knowledge base (plus the ability to draw trend insights from the platform).

“Contagious Interview” refers to a North Korea-aligned, hybrid espionage & financially motivated group/campaign, which has heavily targeted software developers and cryptocurrency-related entities since late 2022. As the group gained further attention this year, we added [objects](https://app.tidalcyber.com/campaigns/92748129-528d-4ac4-bd36-2c3f6fe40e49?tab=3) related to it in May. ATT&CK added a [Contagious Interview object](https://app.tidalcyber.com/groups/b436d32f-2667-5e00-a3d8-f58d2d5666d4) in v18 (late October), which we merged with our existing content.

Late last week, NVISO researchers [shared](https://blog.nviso.eu/2025/11/13/contagious-interview-actors-now-utilize-json-storage-services-for-malware-delivery/) details of newly observed Contagious Interview activity. Our [new Tidal Cyber object](https://app.tidalcyber.com/campaigns/219d6dc1-178d-4fc6-aaa4-362327526f9a?tab=3) clearly highlights the group’s evolving behaviors – while key Resource Development, Initial Access, and Impact Techniques continue to be observed, several new ones were featured in recent intrusions (red arrows in graphic), notably in the early- and late (Collection & Exfil) stages of the group’s attacks. Our Procedures data reveal a similar trend: three of 12 identified Sightings “cluster” with previously observed Sightings, but the rest were not considered similar to existing Sightings.

**11/19/25: Contagious Interview Q4 2025 Activity – Spotlight Procedures**

- **PS1031234: Tsunami Payload adds Windows Defender exceptions, creates scheduled tasks, and downloads next stage from Pastebin** 
    - The 'Tsunami Payload' component of InvisibleFerret performs the following actions: Adds exceptions to Windows Defender; Creates scheduled tasks; Downloads the next stage from Pastebin.

> **Threat-Led Defense commentary**: One of the few recent Sightings that does cluster with previously observed Procedures. Defensive strategies should prioritize comprehensive monitoring, auditing, and restriction of scheduled task creation and execution.

- **PS1031188: Fetch and execute obfuscated JavaScript code from JSON storage services in Node.js projects** 
    - A spotlight of NVISO’s blog, the actors’ trojanized Node.js project is designed to fetch obfuscated JavaScript code from a JSON storage service (e.g., JSON Keeper) using the URL decoded from a config file. The code is imported and executed in *server/controllers/userController.js*.

> **Threat-Led Defense commentary**: Inspect project configuration files for signs of malicious activity. And never run code from unknown repositories, or from apparent “recruiters”, including as part of an interview process (especially in cases where contact was recently initiated).

[View full post](https://www.tidalcyber.com/threat-updates/threat-intel-content-update-11/19/2025)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Tidal Cyber"
  },
  "dateModified" : "2025-11-20T14:00:03.450Z",
  "datePublished" : "2025-11-20T14:00:02Z",
  "headline" : "Threat Intel Content Update: 11/19/2025",
  "image" : {
    "@type" : "ImageObject",
    "height" : 1667,
    "url" : "https://21164103.fs1.hubspotusercontent-na1.net/hubfs/21164103/Threat%20Intel%2011.19.25.jpg",
    "width" : 3000
  },
  "mainEntityOfPage" : "https://www.tidalcyber.com/threat-updates/threat-intel-content-update-11/19/2025",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Threat Intelligence Content Updates"
  }
}
```