s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-py.invisibleferret

📛 Threat Title

Malware family: InvisibleFerret

Category: InvisibleFerret First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `py.invisibleferret`. Printable name: InvisibleFerret.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain py.invisibleferret VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.invisibleferret

IOC database

Type
domain
Value
py.invisibleferret
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-py.invisibleferret

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.invisibleferret

References (1)

Remediations (10)

  • web:any.run

    Discover a detailed technical analysis of the InvisibleFerret malware that targets businesses across different industries.

  • web:anyrun.substack.com

    InvisibleFerret is a Python-based malware that, at first glance, shows a disorganized structure and unnecessary escaping sequences, giving a glimpse of what lies ahead if we dare to explore the code further. A quick look reveals a compact initialization of hardcoded constants used to install dependencies via pip, which are later reused multiple times throughout its execution.

  • web:attack.mitre.org

    InvisibleFerret is a modular python malware that is leveraged for data exfiltration and remote access capabilities. [1] [2] [3] InvisibleFerret consists of four modules: main, payload, browser, and AnyDesk. [1] InvisibleFerret malware has been leveraged by North Korea-affiliated threat actors identified as DeceptiveDevelopment or Contagious Interview since 2023. [4] [2] [3] [5] InvisibleFerret ...

  • web:cybersecuritynews.com

    InvisibleFerret , the primary malware , demonstrates a sophisticated design despite its messy code. Key features include: Data Harvesting: It actively seeks source code, cryptocurrency wallets, user credentials, and sensitive files by targeting browser data, clipboard contents, and system directories like Documents and Downloads.

  • web:github.com

    InvisibleFerret is a Python-based malware designed for corporate espionage, capable of stealing sensitive files, clipboard data, and user credentials while targeting browser extensions like crypto wallets. It employs techniques like FTP for exfiltration, clipboard monitoring, and keylogging. It is deployed after BeaverTail and its part of the Contagious Interview / DevPopper campaign ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the InvisibleFerret malware family including references, samples and yara signatures.

  • web:news.backbox.org

    The Ferrets InvisibleFerret is a Python -based malware that, at first glance, shows a disorganized structure and unnecessary escaping sequences, giving a glimpse of what lies ahead if we dare to explore the code further. A quick look reveals a compact initialization of hardcoded constants used to install dependencies via pip, which are later reused multiple times throughout its execution ...

  • web:www.cybersecurity-insiders.com

    Explore InvisibleFerret , the Lazarus APT's new backdoor, detailing how it operates, evades detection, and the cyber defenses needed to counter it.

  • web:www.microsoft.com

    This detection is related to a North Korean threat actor campaign leveraging the InvisibleFerret malware to target individuals and organizations. The campaign aims to steal sensitive information, including browser data, cryptocurrency wallets, and system credentials, for financial gain.

  • web:www.travismathison.com

    The adversary uses custom malware families BeaverTail and InvisibleFerret , remote monitoring and management tools (RMMs), and malicious Node.js applications to deliver malware to victims. They also infiltrate corporate environments through malicious insiders, often hired as full-time equivalents directly or via contracting organizations.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.