InvisibleFerret
MITRE ATT&CK: S1245 View on attack.mitre.org
Aliases: InvisibleFerret
- First seen
- 2023-01-01 00:00:00
- Malware type
- rat, dropper
- Family
- Malware family
- Operating systems
- linux, macos, windows
- Related IoCs
- 49 (29 malicious)
- Last IoC activity
- 2026-09-01 20:34:04
- Profile updated
- 2026-07-07 13:14:57
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Targeted regions: country_code:kr country_code:us country_code:jp
Context
InvisibleFerret is a modular python malware that is leveraged for data exfiltration and remote access capabilities. InvisibleFerret consists of four modules: main, payload, browser, and AnyDesk. InvisibleFerret malware has been leveraged by North Korea-affiliated threat actors identified as DeceptiveDevelopment or Contagious Interview since 2023. InvisibleFerret has historically been introduced to the victim environment through the use of the BeaverTail malware.
Recent IoC activity
29 malicious indicators in Maltiverse are attributed to InvisibleFerret (S1245). The 20 most recently updated:
Detection coverage
- 1 YARA rules
- 555 Sigma rules
Malware & tools used
- Financial Theft (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Input Capture (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Selective Exclusion (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Software Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- Keylogging (attack-pattern)
- Local Account (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Service Stop (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Launch Agent (attack-pattern)
- XDG Autostart Entries (attack-pattern)
- Remote Access Tools (attack-pattern)
- System Location Discovery (attack-pattern)
- Python (attack-pattern)
- Hidden Window (attack-pattern)
- Non-Standard Port (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Local Data Staging (attack-pattern)
- Password Managers (attack-pattern)
- Web Protocols (attack-pattern)
Used by threat actors
- Contagious Interview (threat-actor)
Detection rules
- SEKOIA_Apt_Lazarus_Backdoored_Jslib (yara-rule)
Reports & references
- Palo Alto Unit 42 — Two Campaigns By North Korea Bad Actors Target Job Hunters (report)
- Palo Alto Unit 42 — Fake North Korean It Worker Activity Cluster (report)
- Trend Micro — Russian Infrastructure North Korean Cybercrime (report)
- zscaler.com — Pyongyang Your Payroll Rise North Korean Remote Workers West (report)
- Microsoft — Contagious Interview Malware Delivered Through Fake Developer Job Interviews (report)
- securitylabs.datadoghq.com — Tenacious Pungsan Dprk Threat Actor Contagious Interview (report)
- Palo Alto Unit 42 — North Korean Threat Actors Lure Tech Job Seekers As Fake Recruiters (report)
- esentire.com — Bored Beavertail Invisibleferret Yacht Club A Lazarus Lure Pt 2 (report)
- recordedfuture.com — Inside The Scam North Koreas It Worker Threat (report)
- ESET — Deceptivedevelopment Targets Freelance Developers (report)
- socket.dev — North Korean Apt Lazarus Targets Developers With Malicious Npm Package (report)
- blog.nviso.eu — Contagious Interview Actors Now Utilize Json Storage Services For Malware Delivery (report)
- www-cdn.anthropic.com — B2A76C6F6992465C09A6F2Fce282F6C0Cea8C200 (report)
- jp.security.ntt — Contagious Interview Ottercookie (report)
- ESET — Deceptivedevelopment From Primitive Crypto Theft To Sophisticated Ai Based Deception (report)
- doi.org — Arxiv.2505.21725 (report)
- radar.securityalliance.org — Vs Code Tasks Abuse By Contagious Interview Dprk (report)
- gitlab-com.gitlab.io — North Korean Malware Sept 2025 (report)
- stacklok.com — Dependency Hijacking Dissecting North Koreas New Wave Of Defi Themed Open Source Attacks Targeting Developers (report)
- redasgard.com — Hunting Lazarus Contagious Interview C2 Infrastructure (report)
- medium.com — How A Fake Ai Recruiter Delivers Five Staged Malware Disguised As A Dream Job 64Cc68Fec263 (report)
- socket.dev — North Korean Contagious Interview Campaign Drops 35 New Malicious Npm Packages (report)
- socket.dev — Contagious Interview Campaign Escalates 67 Malicious Npm Packages (report)
- socket.dev — Lazarus Expands Malicious Npm Campaign 11 New Packages Add Malware Loaders And Bitbucket (report)
- group-ib.com — Apt Lazarus Python Scripts (report)
External references
- mitre-attack — S1245
- Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024
- Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025
- ESET Contagious Interview BeaverTail InvisibleFerret February 2025
- Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024
- PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023
- PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy