InvisibleFerret is a Python-based backdoor associated with North Korean threat actors conducting the Contagious Interview campaign, including activity tracked as WaterPlum, Famous Chollima, and UNC5342. It provides remote access to compromised systems, including remote-shell functionality, and supports continued access and data exfiltration. It runs on Windows, macOS, and Linux.
InvisibleFerret is commonly deployed as a second-stage payload by BeaverTail, which downloads and executes it after its initial information-collection workflow. On Windows, BeaverTail can install a portable Python runtime when needed to execute the backdoor; on other supported systems, it uses Python 3. Distribution involves fraudulent recruitment processes, malicious npm packages, and seemingly legitimate developer projects presented as technical-interview assignments or troubleshooting materials. These operations target software developers, engineers, freelance IT professionals, and cryptocurrency, blockchain, and Web3 specialists worldwide. Compromised developer systems can provide a foothold for subsequent intrusions into employers’ or clients’ environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“利用 Windows 系统的零日漏洞 CVE-2024-38193……攻击者瞬间获得 SYSTEM 权限,部署 InvisibleFerret 后门。”
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
InvisibleFerret Python-based backdoor used to access compromised systems
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
332 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
170 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family distributed by the North Korean-linked WaterPlum campaign through fraudulent technical interviews and developer-task lures.
A named malicious payload delivered through trojanized NPM packages in WaterPlum's fake-job-interview campaign. The campaign used remote-access trojans and infostealers to steal browser credentials, keystrokes, screenshots, wallet private keys, seed phrases, and identity documents.
A malware family delivered through fake job-interview downloads by WaterPlum. The campaign's malware enables theft of authentication data, cryptocurrency-wallet material, files, clipboard contents, keystrokes, and screenshots, as well as follow-on access.
The post links to Atlassian's "Disrupting Contagious Interview" publication and tags #InvisibleFerret alongside other malware names.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.