InvisibleFerret is a Python-based modular malware family associated with North Korea-linked developer-targeting intrusion activity including Contagious Interview, DeceptiveDevelopment, and clusters tracked as DEV#POPPER, Famous Chollima, and Lazarus-linked operations. It is typically deployed as a later-stage implant after BeaverTail or related JavaScript loaders and is used against software developers, especially those involved in cryptocurrency, Web3, blockchain, and technology projects. Delivery has been observed through fake job offers, trojanized coding challenges, malicious repositories, Visual Studio Code task abuse, fake interview or conferencing software, and poisoned software packages.
InvisibleFerret combines remote-access and information-stealing functionality. Reported capabilities include theft of browser credentials, session cookies, saved form data, payment-card data, SSH private keys, environment-variable secrets such as cloud and developer tokens, cryptocurrency wallet data, password-manager material, and other developer artifacts. Variants also support keylogging, clipboard capture or selective clipboard theft, host fingerprinting, file discovery, staged collection of stolen data prior to exfiltration, and remote command execution over socket- or TCP-based command and control. Some versions can upload data through alternate channels such as FTP or Telegram.
The malware is cross-platform, with activity documented on Windows, macOS, and Linux. Windows-focused components have included keylogging, clipboard theft, startup-folder or scheduled-task persistence, and deployment of remote-access software such as AnyDesk. macOS variants have established persistence through LaunchAgents. Additional modules have been used to replace or trojanize browser wallet extensions and to maintain longer-term access on selected victims. More recent evolution includes migration from readable Python scripts to compiled extension modules such as Windows .pyd and macOS .so components, likely to hinder analysis and evade script-focused defenses.
InvisibleFerret is best characterized as a cross-platform backdoor with substantial infostealing functionality, used for credential theft, cryptocurrency theft, persistent access, and post-compromise operator control in DPRK-linked social-engineering and software supply-chain campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The unpacked chain is the familiar Lazarus toolkit: a Beavertail loader that fingerprints the host OS and selects an InvisibleFerret implant (also reported as DEV#POPPER RAT and OmniStealer) for credential theft, browser-data theft, wallet exfiltration, and socket.io-based C2.
It targets developers with fake job offers to deliver the JADESNOW loader and INVISIBLEFERRET backdoor.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
PolinRider is a DPRK-linked supply-chain campaign... takes over legitimate GitHub accounts and quietly injects an obfuscated JavaScript loader into repositories the maintainer already owns.
runOptions의 runOn 옵션이 folderOpen으로 설정되어 있어 레포지토리에 대한 폴더가 VSCode에서 열릴 경우 자동으로 삽입된 명령어가 실행되는 방식이다.
Malicious npm package posing as a Tailwind utility; functional decoy in index.ts
The starting point of the attack is a hidden Microsoft Visual Studio Code (VS Code) task named "eslint-check" that's configured with the "runOn: 'folderOpen'" option to trigger the execution of arbitrary code when the folder is opened as a workspace folder in an IDE like VS Code or Cursor.
OS 、ブラウザで保有している認証情報やブラウザ拡張機能としてインストールされている暗号資産ウォレット関連ファイルも窃取し、 C2 サーバへアップロードします。
It's also equipped to harvest developer-oriented information like Git credentials, GitHub CLI hosts.yml, GitHub Desktop logs, VS Code, and global storage, as well as data from Windows Credential Manager, Linux Secret Service, KDE Wallet, macOS Keychain...
InvisibleFerret implant (also reported as DEV#POPPER RAT and OmniStealer) for credential theft, browser-data theft, wallet exfiltration, and socket.io-based C2.
hxxp://[악성코드 다운로드용 C&C 서버]:1244/key ... /j/[캠페인 ID] 에서 Beavertail 다운로드 ... /uploads 로 업로드한다.
For FTP uploads, the C&C server provides the domain, username, and password.
The loader still resolves its second stage from blockchain dead-drops across TRON, Aptos, and BNB Smart Chain, decrypts it with embedded XOR keys, and runs it through eval().
273 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
133 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as an additional artifact family defenders should check for on Windows systems during incident response.
A Lazarus implant used for credential theft, browser-data theft, wallet exfiltration, and socket.io-based command-and-control.
Python malware composed of multiple scripts. It provides backdoor capability over sockets, supports command execution, self-deletion, keylogging and clipboard logging, file upload and FTP exfiltration, dead-drop/payload retrieval, AnyDesk deployment for remote access, and browser/crypto-wallet manipulation including replacement of MetaMask and Rabby Wallet extensions.
Python-based malware composed of multiple scripts. It provides backdoor access, executes commands, uploads files, performs keylogging and clipboard theft, can deploy additional payloads, establish persistence, install remote access software, and replace legitimate crypto wallet browser extensions with malicious versions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.