InvisibleFerret

MITRE ATT&CK: S1245 View on attack.mitre.org

Aliases: InvisibleFerret

First seen
2023-01-01 00:00:00
Malware type
rat, dropper
Family
Malware family
Operating systems
linux, macos, windows
Related IoCs
49 (29 malicious)
Last IoC activity
2026-09-01 20:34:04
Profile updated
2026-07-07 13:14:57

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Targeted regions: country_code:kr country_code:us country_code:jp

Context

InvisibleFerret is a modular python malware that is leveraged for data exfiltration and remote access capabilities. InvisibleFerret consists of four modules: main, payload, browser, and AnyDesk. InvisibleFerret malware has been leveraged by North Korea-affiliated threat actors identified as DeceptiveDevelopment or Contagious Interview since 2023. InvisibleFerret has historically been introduced to the victim environment through the use of the BeaverTail malware.

Recent IoC activity

29 malicious indicators in Maltiverse are attributed to InvisibleFerret (S1245). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname pub-06714264305c44ea94491c0c8d961a87.r2.dev 2026-09-03 1
hostname pub-acf013a9b65140b7b58cc3c104ee7105.r2.dev 2026-09-02 1
file sample 07183a60ebcb02546c53e82d92da3ddcf447d7a1438496c4437ec06b4d9eb287_cavity.py 2026-08-15 1
file sample a6faea343b069ecc37f31392f36a533c6277530c6aabab90c6dedbd7429ecde1_stack.py 2026-08-14 2
file sample 10f86be3e564f2e463e45420eb5f9fbdb14f7427eac665cd9cc7901efbc4cc59_stack.py 2026-08-13 1
file sample 486a9a79bbb81abee2e81679ace6267c3f3e37d9b8c8074f9ec7aebc9be75cdd_zipper.py 2026-08-12 1
file sample 5d1f6900788d983ad8cb03a2aedc07523b4d910ad6f722bed123b7a64e280f3e_cavity.py 2026-08-11 1
file sample 9ece783ac52c9ec2f6bdfa669763a7ed1bbb24af1e04e029a0a91954582690cf_cavity.py 2026-07-30 1
file sample 07183a60ebcb02546c53e82d92da3ddcf447d7a1438496c4437ec06b4d9eb287.py 2026-07-29 2
file sample 10f86be3e564f2e463e45420eb5f9fbdb14f7427eac665cd9cc7901efbc4cc59.py 2026-07-29 2
file sample 9ece783ac52c9ec2f6bdfa669763a7ed1bbb24af1e04e029a0a91954582690cf.py 2026-07-29 2
file sample 9ece783ac52c9ec2f6bdfa669763a7ed1bbb24af1e04e029a0a91954582690cf_stack.py 2026-07-25 1
file sample 10f86be3e564f2e463e45420eb5f9fbdb14f7427eac665cd9cc7901efbc4cc59_cavity.py 2026-07-23 1
file sample 486a9a79bbb81abee2e81679ace6267c3f3e37d9b8c8074f9ec7aebc9be75cdd.py 2026-07-21 2
file sample 5d1f6900788d983ad8cb03a2aedc07523b4d910ad6f722bed123b7a64e280f3e_stack.py 2026-07-18 1
file sample 5d1f6900788d983ad8cb03a2aedc07523b4d910ad6f722bed123b7a64e280f3e_zipper.py 2026-07-18 1
file sample cd3b606d31c9d3c2ee972916f8de9a403caf00f00698fd6b9acece6ff30647c6.py 2026-07-17 2
file sample f3d173ab5408029e92906b8a71474a6f32722d09a89a53b977b5c40ac6e8805c.py 2026-07-17 2
file sample main 2026-07-16 2
URL http://95.216.64.240:1224/client/36/700 2026-07-16 2

Detection coverage

  • 1 YARA rules
  • 555 Sigma rules

Malware & tools used

  • Financial Theft (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Input Capture (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Selective Exclusion (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Software Discovery (attack-pattern)
  • Process Discovery (attack-pattern)
  • Keylogging (attack-pattern)
  • Local Account (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Service Stop (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Launch Agent (attack-pattern)
  • XDG Autostart Entries (attack-pattern)
  • Remote Access Tools (attack-pattern)
  • System Location Discovery (attack-pattern)
  • Python (attack-pattern)
  • Hidden Window (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Password Managers (attack-pattern)
  • Web Protocols (attack-pattern)

Used by threat actors

Detection rules

  • SEKOIA_Apt_Lazarus_Backdoored_Jslib (yara-rule)

Reports & references

  • Palo Alto Unit 42 — Two Campaigns By North Korea Bad Actors Target Job Hunters (report)
  • Palo Alto Unit 42 — Fake North Korean It Worker Activity Cluster (report)
  • Trend Micro — Russian Infrastructure North Korean Cybercrime (report)
  • zscaler.com — Pyongyang Your Payroll Rise North Korean Remote Workers West (report)
  • Microsoft — Contagious Interview Malware Delivered Through Fake Developer Job Interviews (report)
  • securitylabs.datadoghq.com — Tenacious Pungsan Dprk Threat Actor Contagious Interview (report)
  • Palo Alto Unit 42 — North Korean Threat Actors Lure Tech Job Seekers As Fake Recruiters (report)
  • esentire.com — Bored Beavertail Invisibleferret Yacht Club A Lazarus Lure Pt 2 (report)
  • recordedfuture.com — Inside The Scam North Koreas It Worker Threat (report)
  • ESET — Deceptivedevelopment Targets Freelance Developers (report)
  • socket.dev — North Korean Apt Lazarus Targets Developers With Malicious Npm Package (report)
  • blog.nviso.eu — Contagious Interview Actors Now Utilize Json Storage Services For Malware Delivery (report)
  • www-cdn.anthropic.com — B2A76C6F6992465C09A6F2Fce282F6C0Cea8C200 (report)
  • jp.security.ntt — Contagious Interview Ottercookie (report)
  • ESET — Deceptivedevelopment From Primitive Crypto Theft To Sophisticated Ai Based Deception (report)
  • doi.org — Arxiv.2505.21725 (report)
  • radar.securityalliance.org — Vs Code Tasks Abuse By Contagious Interview Dprk (report)
  • gitlab-com.gitlab.io — North Korean Malware Sept 2025 (report)
  • stacklok.com — Dependency Hijacking Dissecting North Koreas New Wave Of Defi Themed Open Source Attacks Targeting Developers (report)
  • redasgard.com — Hunting Lazarus Contagious Interview C2 Infrastructure (report)
  • medium.com — How A Fake Ai Recruiter Delivers Five Staged Malware Disguised As A Dream Job 64Cc68Fec263 (report)
  • socket.dev — North Korean Contagious Interview Campaign Drops 35 New Malicious Npm Packages (report)
  • socket.dev — Contagious Interview Campaign Escalates 67 Malicious Npm Packages (report)
  • socket.dev — Lazarus Expands Malicious Npm Campaign 11 New Packages Add Malware Loaders And Bitbucket (report)
  • group-ib.com — Apt Lazarus Python Scripts (report)

External references