#InvisibleFerret
Slovenia's CERT has published a report on BeaverTail & InvisibleFerret, two malware samples used by North Korean hackers to target crypto developers

www.cert.si/tz016/
SI-CERT TZ016 / BeaverTail & InvisibleFerret - SI CERT
Cilj napadalcev je bil pridobiti shranjene podatke spletnih brskalnikov (shranjena gesla, seje, zgodovina, itd.) in kreditne kartice.
www.cert.si
February 18, 2025 at 5:40 PM
North Korean APT "Contagious Interview" registers three cryptocurrency companies (BlockNovas LLC, Angeloper Agency, and SoftGlide LLC) to infect cryptocurrency job applicants with BeaverTail, InvisibleFerret, and OtterCookie malware

www.silentpush.com/blog/contagi...
Contagious Interview (DPRK) Launches a New Campaign Creating Three Front Companies to Deliver a Trio of Malware: BeaverTail, InvisibleFerret, and OtterCookie
Contagious Interview (DPRK) have launched a new campaign involving three front companies that deliver BeaverTail, InvisibleFerret, and OtterCookie malware.
www.silentpush.com
April 25, 2025 at 8:30 AM
The GitLab security team has identified new infrastructure used to deploy BeaverTail and InvisibleFerret, malware linked to North Korean hackers.

gitlab-com.gitlab.io/gl-security/...
September 17, 2025 at 11:53 PM
Threat analysts have uncovered that North Korea's Contagious Interview APT group is using three front companies to distribute malware strains BeaverTail, InvisibleFerret, and OtterCookie through fake cryptocurrency job offers. #CyberSecurity #Malware www.silentpush.com/blog/contagi...
Contagious Interview (DPRK) Launches a New Campaign Creating Three Front Companies to Deliver a Trio of Malware: BeaverTail, InvisibleFerret, and OtterCookie
Contagious Interview (DPRK) have launched a new campaign involving three front companies that deliver BeaverTail, InvisibleFerret, and OtterCookie malware.
www.silentpush.com
April 25, 2025 at 1:14 AM
Fresh new video with @silascutler.bsky.social and @dennisf.bsky.social discussing the BeaverTail and InvisibleFerret malware and the DPRK threat actor landscape.
youtu.be/z-KImQiHRck?...
The Big Story: BeaverTail, InvisibleFerret and the Carnival of North Korean Threats
YouTube video by Censys
youtu.be
April 25, 2025 at 8:52 PM
Super detailed report from @silentpush.bsky.social exposing a North Korean cyber op that used at least two companies registered in the U.S. target devs: www.silentpush.com/blog/contagi...
April 24, 2025 at 8:47 PM
North Korean hackers (DeceptiveDevelopment) use fake job postings on LinkedIn & Upwork to infect developers (Windows, Linux, macOS) with malware (BeaverTail & InvisibleFerret). Malware steals crypto & credentials, granting remote access via AnyDesk.#DeceptiveDevelopmentMalware
February 21, 2025 at 10:39 AM
«Contagious Interview (DPRK) Launches a New Campaign Creating Three Front Companies to Deliver a Trio of Malware: BeaverTail, InvisibleFerret, and OtterCookie»

www.silentpush.com/blog/contagi...
Contagious Interview (DPRK) Launches a New Campaign Creating Three Front Companies to Deliver a Trio of Malware: BeaverTail, InvisibleFerret, and OtterCookie
Contagious Interview (DPRK) have launched a new campaign involving three front companies that deliver BeaverTail, InvisibleFerret, and OtterCookie malware.
www.silentpush.com
April 25, 2025 at 10:04 AM
InvisibleFerret Malware Now Ships as .pyd and .so Files to Evade Script Detection
InvisibleFerret Malware Now Ships as .pyd and .so Files to Evade Script Detection
A North Korea-linked hacker group has quietly upgraded one of its most dangerous tools, making it harder for security software to detect. InvisibleFerret, an information-stealing malware tied to the threat actor known as Void Dokkaebi (also tracked as Famous Chollima), has been repackaged into a format that slips past many traditional detection methods. Instead of arriving as plain Python scripts, it now comes disguised as compiled binary files. Void Dokkaebi has long targeted software developers who hold cryptocurrency wallet credentials, signing keys, and access to build pipelines or production systems. The group poses as recruiters from cryptocurrency or AI firms, convincing developers to clone and run code repositories as part of fake job interviews. Once executed, the malicious code begins a multi-stage infection designed to steal sensitive data and maintain persistent access. Analysts at Trend Micro identified that InvisibleFerret has now been obfuscated using Cython, a tool that converts Python code into native binaries.  Trend Micro said in a report shared with Cyber Security News (CSN) that the malware is distributed as .pyd files on Windows and .so files on macOS, rather than readable Python scripts. This means existing detection rules for Python-based threats may no longer identify the malware. The update preserves InvisibleFerret’s full range of capabilities. The malware can open backdoor access, steal browser credentials, monitor clipboard activity, log keystrokes, and target cryptocurrency wallets. The companion loader known as BeaverTail has also evolved from a basic downloader into a broader threat with its own credential harvesting and wallet-targeting functions. The campaign is especially relevant to software developers, crypto users, and organizations whose staff have access to signing keys or CI/CD pipelines. Security teams relying on script-based detections now have a gap in coverage. The shift to compiled binaries represents a calculated attempt to stay ahead of defenders who haven’t updated their detection strategies . InvisibleFerret Malware The core change in this updated variant is the move from Python scripts to Cython-compiled binaries. On Windows, the malware arrives as .pyd files, Python extension modules in DLL format. On macOS, the format is .so, a shared library, and neither type runs independently without a Python interpreter. Infection chain (Source – Trend Micro) To handle this, the infection chain writes a companion .mod script to disk and uses it to launch the compiled binary. Security tools scanning for Python script patterns will not flag anything in these binary files. While IP addresses and port numbers can still be extracted through binary analysis, runtime scripts can override these values with different command-and-control destinations passed as arguments. The malware has four core modules with distinct roles. The mod module handles the initial connection and downloads further payloads. The pad module provides backdoor access and gathers system information. The brw module steals authentication data and credit card details from browsers, while the mc module for macOS installs trojanized wallet extensions and downgrades Chrome to bypass Google’s newer extension security framework. BeaverTail Expands Its Role in the Infection Chain Alongside InvisibleFerret’s repackaging, BeaverTail has grown into a more complex threat . It now operates through four variants: gjs handles data theft and downloads further components, njs provides backdoor functions, zjs steals wallet seed phrases and private keys, and cjs installs trojanized extensions in Chrome and Brave Browser targeting MetaMask, Coinbase Wallet, and Phantom. The execution process (Source – Trend Micro) BeaverTail’s obfuscation has also become notably stronger. The updated code shuffles a large array of Base64 fragments at startup, strips junk characters from encoded strings to defeat simple detection, and uses XOR encryption with a 4-byte key for sensitive strings like file paths. Command-and-control IP addresses are split into halves and swapped before Base64 encoding to further complicate analysis. Defenders are advised to move from script-only detection toward binary-aware approaches that account for extension modules, embedded artifacts, and runtime execution scripts. Teams should watch for Chrome version downgrades on macOS , trojanized wallet extensions, and unusual Python activity in .vscode directory paths. Analysts familiar with earlier InvisibleFerret versions can apply the same deobfuscation methods, since the core logic inside the compiled binaries remains unchanged. Indicators of Compromise (IoCs):- Type Indicator Description File Name mod.pyd Cython-compiled InvisibleFerret module for Windows (main) File Name mod.so Cython-compiled InvisibleFerret module for macOS (main) File Name pad.pyd InvisibleFerret backdoor/payload module for Windows File Name pad.so InvisibleFerret backdoor/payload module for macOS File Name brw.pyd InvisibleFerret browser-stealing module for Windows File Name brw.so InvisibleFerret browser-stealing module for macOS File Name mc.so InvisibleFerret wallet trojanization module for macOS File Name .mod Python execution script that loads and runs the Cython binaries File Name pad0 Runtime execution script for pad module File Name brw0 Runtime execution script for brw module File Name mc0 Runtime execution script for mc module File Path .vscode\mod.pyd / .vscode/mod.so Known drop path for InvisibleFerret main module File Path .vscode\pad.pyd / .vscode/pad.so Known drop path for InvisibleFerret pad module File Path .vscode\brw.pyd / .vscode/brw.so Known drop path for InvisibleFerret brw module File Path .vscode/mc.so Known drop path for InvisibleFerret mc module IP Address 45[.]59[.]160[.]199 C&C server IP address extracted from Cython binary via XOR decoding URL hxxp://ip-api[.]com/json External geolocation lookup abused by BeaverTail (njs) and pad modules URL Pattern /clw/{sType} Windows C&C download path for Cython-compiled InvisibleFerret URL Pattern /clw1/{sType} macOS C&C download path for Cython-compiled InvisibleFerret Build Path /Users/administrator/Pictures/Work/py_module_work/ macOS build environment path embedded in .so binaries Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in Google . The post InvisibleFerret Malware Now Ships as .pyd and .so Files to Evade Script Detection appeared first on Cyber Security News .
cybersecuritynews.com
May 26, 2026 at 9:15 AM
Q1 2025's top 5 malware campaigns (NetSupport RAT, Lynx ransomware, AsyncRAT, Lumma Stealer, InvisibleFerret) employed advanced evasion tactics for persistence and data theft.#AdvancedMalwareEvasionQ12025
February 25, 2025 at 3:03 PM
-Another Spanish spyware vendor shuts down
-47 scammers arrested in Nigeria
-Malware reports on StaryDobry, XCSSET, Zhong Stealer, FrigidStealer, Vgod and BlackLock ransomware
-APT reports on DEEP#DRIVE, Earth Preta, DPRK's BeaverTail & InvisibleFerret
-Default creds in Hirsch building entry systems
February 19, 2025 at 9:37 AM
InvisibleFerret Malware: Technical Analysis - ANY.RUN's Cybersecurity Blog any.run/cybersecurit...
InvisibleFerret Malware: Technical Analysis - ANY.RUN's Cybersecurity Blog
Discover a detailed technical analysis of the InvisibleFerret malware that targets businesses across different industries.
any.run
January 24, 2025 at 7:22 AM
Same Old story coming from North Korea. They are once again trying to gain access to open-source projects to use them in cyberattacks.
#opensource #cybersecurity #northkorea
Developers beware: North Korea is weaponizing GitHub projects
North Korea’s Lazarus Group uses VS Code to deliver InvisibleFerret malware
cybernews.com
January 28, 2026 at 3:49 AM
This specific campaign from Contagious Interview has been going on since last year – there are known public victims – and this campaign has been spreading three malware strains: BeaverTail, InvisibleFerret, and OtterCookie.
April 24, 2025 at 7:44 PM
Silent Push researchers have uncovered 3 cryptocurrency companies that are fronts for North Korean APT group Contagious Interview. BeaverTail, InvisibleFerret & OtterCookie are being spread from this infrastructure to unsuspecting cryptocurrency job applicants. www.silentpush.com/blog/contagi...
April 25, 2025 at 9:32 AM
Void Dokkaebi evolve InvisibleFerret: il malware nordcoreano ora usa Cython per sfuggire agli antivirus
il blog: insicurezzadigitale.com/void-dokkaeb...

#cybersecurity #apt #backdoor #coreadelnord #famouschollima #invisibleferret #malware #voiddokkaebi
May 27, 2026 at 7:28 AM
InvisibleFerret is modular 🐍 Python-based malware that includes spyware and backdoor components, and is also capable of downloading the legitimate AnyDesk remote management and monitoring software for post-compromise activities. 4/6
February 20, 2025 at 8:39 PM
"From fake interviews to malicious repositories: Disrupting Contagious Interview" published by Atlassian. #ContagiousInterview, #BeaverTail, #InvisibleFerret, #FamousChollima, #OtterCookie, #GolangGhost, #PylangGhost https://www.atlassian.com/blog/how-we-build/disrupting-contagious-interview
From fake interviews to malicious repositories: Disrupting Contagious Interview
www.atlassian.com
September 22, 2026 at 5:06 AM
"Contagious Interview (DPRK) Launches a New Campaign Creating Three Front Companies to Deliver a Trio of Malware: BeaverTail, InvisibleFerret, and OtterCookie" www.silentpush.com/blog/contagi...
Contagious Interview (DPRK) Launches a New Campaign Creating Three Front Companies to Deliver a Trio of Malware: BeaverTail, InvisibleFerret, and OtterCookie
Contagious Interview (DPRK) have launched a new campaign involving three front companies that deliver BeaverTail, InvisibleFerret, and OtterCookie malware.
www.silentpush.com
April 24, 2025 at 7:44 PM
The campaign primarily uses two malware families – the first, 🦫 BeaverTail, acts as a simple login stealer, extracting browser databases containing saved logins, and is a downloader for the second stage, InvisibleFerret. 3/6
February 20, 2025 at 8:39 PM
Lazarus Group cible les portefeuilles crypto avec nouveau malware | Phemex News phemex.com/fr/news/arti...
Lazarus Group cible les portefeuilles crypto avec nouveau malware | Phemex News
Une nouvelle variante de malware du groupe Lazarus se cache dans les Git Hooks, ciblant les portefeuilles crypto avec InvisibleFerret et BeaverTail.
phemex.com
May 10, 2026 at 5:53 AM

⚠️ North Korean hackers posing as recruiters infect software developers with cross-platform #malware named "BeaverTail" and "InvisibleFerret," targeting Windows, #Linux, and macOS systems during fake interviews.
thehackernews.com/2023/11/nort...
#cybersecurity #technews
North Korean Hackers Pose as Job Recruiters and Seekers in Malware Campaigns
North Korean hackers posing as recruiters infect software developers with cross-platform malware.
thehackernews.com
November 22, 2023 at 12:46 PM
北朝鮮のハッカーがフリーランス開発者を求人詐欺で標的にしマルウェアを拡散

フリーランスのソフトウェア開発者は、就職面接をテーマにした餌を利用して、BeaverTail および InvisibleFerret として知られるクロスプラットフォームのマルウェア ファミリを配布する進行中のキャンペーンのターゲットになっています。

北朝鮮に関連するこの活動は「DeceptiveDevelopment」というコードネームで呼ばれており、Contagious Interview(別名CL-STA-0240)、DEV#POPPER、Famous Chollima、PurpleBravo、Tenac...
North Korean Hackers Target Freelance Developers in Job Scam to Deploy Malware
North Korean hackers use fake job interviews on Upwork and GitHub to infect crypto developers with BeaverTail and InvisibleFerret malware, stealing cr
thehackernews.com
July 19, 2025 at 8:26 PM