TF-MAL-py.invisibleferret
📛 Threat Title
Malware family: InvisibleFerret
Description
ThreatFox malware family `py.invisibleferret`. Printable name: InvisibleFerret.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
py.invisibleferret
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.invisibleferret
IOC database
- Type
- domain
- Value
py.invisibleferret- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-py.invisibleferret
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.invisibleferret
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:any.run
Discover a detailed technical analysis of the InvisibleFerret malware that targets businesses across different industries.
-
web:anyrun.substack.com
InvisibleFerret is a Python-based malware that, at first glance, shows a disorganized structure and unnecessary escaping sequences, giving a glimpse of what lies ahead if we dare to explore the code further. A quick look reveals a compact initialization of hardcoded constants used to install dependencies via pip, which are later reused multiple times throughout its execution.
-
web:attack.mitre.org
InvisibleFerret is a modular python malware that is leveraged for data exfiltration and remote access capabilities. [1] [2] [3] InvisibleFerret consists of four modules: main, payload, browser, and AnyDesk. [1] InvisibleFerret malware has been leveraged by North Korea-affiliated threat actors identified as DeceptiveDevelopment or Contagious Interview since 2023. [4] [2] [3] [5] InvisibleFerret ...
-
web:cybersecuritynews.com
InvisibleFerret , the primary malware , demonstrates a sophisticated design despite its messy code. Key features include: Data Harvesting: It actively seeks source code, cryptocurrency wallets, user credentials, and sensitive files by targeting browser data, clipboard contents, and system directories like Documents and Downloads.
-
web:github.com
InvisibleFerret is a Python-based malware designed for corporate espionage, capable of stealing sensitive files, clipboard data, and user credentials while targeting browser extensions like crypto wallets. It employs techniques like FTP for exfiltration, clipboard monitoring, and keylogging. It is deployed after BeaverTail and its part of the Contagious Interview / DevPopper campaign ...
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the InvisibleFerret malware family including references, samples and yara signatures.
-
web:news.backbox.org
The Ferrets InvisibleFerret is a Python -based malware that, at first glance, shows a disorganized structure and unnecessary escaping sequences, giving a glimpse of what lies ahead if we dare to explore the code further. A quick look reveals a compact initialization of hardcoded constants used to install dependencies via pip, which are later reused multiple times throughout its execution ...
-
web:www.cybersecurity-insiders.com
Explore InvisibleFerret , the Lazarus APT's new backdoor, detailing how it operates, evades detection, and the cyber defenses needed to counter it.
-
web:www.microsoft.com
This detection is related to a North Korean threat actor campaign leveraging the InvisibleFerret malware to target individuals and organizations. The campaign aims to steal sensitive information, including browser data, cryptocurrency wallets, and system credentials, for financial gain.
-
web:www.travismathison.com
The adversary uses custom malware families BeaverTail and InvisibleFerret , remote monitoring and management tools (RMMs), and malicious Node.js applications to deliver malware to victims. They also infiltrate corporate environments through malicious insiders, often hired as full-time equivalents directly or via contracting organizations.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.