InvisibleFerret is a Python-based malware family used in North Korea-linked Contagious Interview and related supply-chain operations, often alongside the JavaScript loader and stealer BeaverTail. It is commonly deployed as a second-stage payload after social-engineering lures such as fake job interviews, malicious coding assessments, trojanized repositories, compromised npm or Go packages, malicious VS Code tasks, Git hooks, and ClickFix-style instructions. Public reporting also tracks overlapping components or aliases including DEV#POPPER RAT and OmniStealer in some intrusion chains.
InvisibleFerret functions as both an infostealer and remote-access backdoor. Reported capabilities include theft of browser login data, autofill data, payment-card information, session cookies, cryptocurrency-wallet data, browser-extension data, SSH private keys, environment-variable secrets, and other developer or cloud-related credentials. On Windows, observed variants also support keylogging and clipboard capture. Multiple reports describe command execution, file discovery and upload, browser termination, download and execution of additional modules, and exfiltration through attacker-controlled channels. Some variants have been observed installing or configuring remote-access software to maintain operator access.
The malware is modular and has been described as comprising multiple Python scripts, including downloader, backdoor, browser-stealer, and keylogging components. It uses layered obfuscation and concealed execution techniques, including encrypted or encoded Python stages and hidden process creation flags, to reduce visibility and hinder analysis. In several campaigns, InvisibleFerret has been delivered cross-platform and used against Windows, macOS, and Linux systems, with a strong emphasis on developers, Web3 organizations, cryptocurrency users, and software supply-chain targets.
InvisibleFerret is closely associated with financially motivated DPRK activity focused on credential theft and cryptocurrency theft, but it also provides broader post-compromise access consistent with long-term intrusion objectives. In observed chains, BeaverTail frequently performs initial collection and staging, then loads InvisibleFerret to expand collection, enable remote control, and deepen compromise on infected hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this way, the code snippet above located within the catch block prevents the main payload (in this case, ‘invisible ferret’) from needing to be written directly into the project’s main code...
They have been using malware called BeaverTail or InvisibleFerret in Contagious Interview campaign since around 2023, they started using new malware since September 2024.
It targets developers with fake job offers to deliver the JADESNOW loader and INVISIBLEFERRET backdoor.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Earlier this week, I read a Socket blog about two compromised Joyfill beta releases. Joyfill is a legitimate digital form and PDF automation platform, and the poisoned versions contain malware that deploys a remote-access trojan (RAT).
DPRK’s goal is to compromise developer machines and accounts to silently propagate malicious code, clone repositories, and push backdoored commits without active human intervention.
T1059 Command and Scripting Interpreter Multiple stages rely on Scripting Interpreters like JavaScript, PowerShell and Python.
The Linux ClickFix command uses wget to download a script file, which is piped directly into bash .
The update.vbs script is a VisualBasic script that performs two actions ... Executes the nvidiasdk.exe executable, which contains BeaverTail.
Odgovor shrani v datoteko .npl v domači mapi uporabnika in jo nato izvrši s Python interpretorjem.
After the request, the flow code captures the request’s response, stores it in the token object, and executes the content using the eval() function.
koda pa je bila verjetno zamaskirana oz. obfuskirana z uporabo odprto-kodnega obfuskatorja javascript-obfuscator
napadalci lažno predstavljajo kot iskalci zaposlitve ali pa želijo kakšno drugo sodelovanje z neko organizacijo
A committed .vscode/tasks.json with runOptions.runOn: 'folderOpen' executes the moment the project folder opens in VS Code, Cursor, Antigravity, or GitHub Desktop, bypassing npm v12's lifecycle-script protections entirely.
These guardrails delay automated identification and linking of the threat actor’s infrastructure and reduce their footprint in security sandboxes.
If a request is made without a specific user agent, the threat actor’s service responds with a decoy payload... These guardrails delay automated identification and linking of the threat actor’s infrastructure and reduce their footprint in security sandboxes.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
ssh_clip Vrne zabeležene vnose (keylogger). Keylogger je aktiven samo na Windows OS.
covering credential theft, browser-data theft, crypto-wallet exfiltration, and keylogging.
krade gesla in kreditne kartice shranjenih v spletnih brskalnikih
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Omogoča iskanje datotek po sistemu ... Pridobi datoteke iz zunanjih diskov in map za dokumente ter prenose
Patchwork dumped the login data database from \AppData\Local\Google\Chrome\User Data\Default\Login Data ... BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from /.mozilla/firefox/ for exfiltration.
A socket.io channel gives the actor interactive command execution, file upload and download, and clipboard access.
To naredi s HTTP POST zahtevo ... hxxp://23[.]106.253.221:1244/keys ... Pridobljene podatke pošlje nadzornemu strežniku preko HTTP POST zahtev
začne komunikacijo, ki poteka preko TCP protokola. V tem primeru je naslov C2 strežnika sledeč: 173[.]211.106.101:1244
331 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
145 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote-access trojan delivered as a follow-on payload in the PolinRider chain, providing interactive command execution and persistence, including injection into developer applications.
Named malware mentioned in connection with the post, but only as a hashtag without further detail.
Mentioned as another DPRK-linked malware family used as a comparison for the actors' shift toward compiled binaries for stealth.
Referenced only as an additional artifact family defenders should check for on Windows systems during incident response.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.