InvisibleFerret is a modular Python-based remote-access trojan and information stealer associated with DPRK-linked Contagious Interview activity, including clusters tracked as Lazarus Group, Famous Chollima, WaterPlum, UNC5342, and PolinRider. It is commonly deployed as a second-stage payload by the Node.js-based BeaverTail loader following social-engineering lures involving fraudulent job interviews, coding assessments, malicious software-development repositories, and, in some operations, ClickFix prompts or blockchain-backed payload delivery. The malware targets Windows, macOS, and Linux systems, with an emphasis on developers and organizations involved in cryptocurrency, Web3, blockchain, DeFi, financial technology, and related sectors.
InvisibleFerret provides remote command execution and can collect system information; steal browser-stored login credentials, autofill and payment data, browser extensions, cryptocurrency-wallet data, and session-related browser data; search for and exfiltrate sensitive files; and upload collected material through command-and-control or alternative transfer mechanisms. Its modules have supported keylogging and clipboard collection, browser-process termination, additional payload retrieval, and installation or configuration of remote-access software. Certain Windows-focused variants establish persistence and impair endpoint defenses, while other variants manipulate browser-extension data and settings to target cryptocurrency wallets. The malware uses layered encoding and encryption to hinder analysis and can operate over socket-based command-and-control channels.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“The payload returned by the smart contract is a variant of InvisibleFerret, one of whose objectives is to steal cryptocurrencies.”
In this way, the code snippet above located within the catch block prevents the main payload (in this case, ‘invisible ferret’) from needing to be written directly into the project’s main code...
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
Earlier this week, I read a Socket blog about two compromised Joyfill beta releases. Joyfill is a legitimate digital form and PDF automation platform, and the poisoned versions contain malware that deploys a remote-access trojan (RAT).
DPRK’s goal is to compromise developer machines and accounts to silently propagate malicious code, clone repositories, and push backdoored commits without active human intervention.
T1059 Command and Scripting Interpreter Multiple stages rely on Scripting Interpreters like JavaScript, PowerShell and Python.
The Linux ClickFix command uses wget to download a script file, which is piped directly into bash .
The update.vbs script is a VisualBasic script that performs two actions ... Executes the nvidiasdk.exe executable, which contains BeaverTail.
Odgovor shrani v datoteko .npl v domači mapi uporabnika in jo nato izvrši s Python interpretorjem.
After the request, the flow code captures the request’s response, stores it in the token object, and executes the content using the eval() function.
koda pa je bila verjetno zamaskirana oz. obfuskirana z uporabo odprto-kodnega obfuskatorja javascript-obfuscator
napadalci lažno predstavljajo kot iskalci zaposlitve ali pa želijo kakšno drugo sodelovanje z neko organizacijo
A committed .vscode/tasks.json with runOptions.runOn: 'folderOpen' executes the moment the project folder opens in VS Code, Cursor, Antigravity, or GitHub Desktop, bypassing npm v12's lifecycle-script protections entirely.
These guardrails delay automated identification and linking of the threat actor’s infrastructure and reduce their footprint in security sandboxes.
If a request is made without a specific user agent, the threat actor’s service responds with a decoy payload... These guardrails delay automated identification and linking of the threat actor’s infrastructure and reduce their footprint in security sandboxes.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
ssh_clip Vrne zabeležene vnose (keylogger). Keylogger je aktiven samo na Windows OS.
krade gesla in kreditne kartice shranjenih v spletnih brskalnikih
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Omogoča iskanje datotek po sistemu ... Pridobi datoteke iz zunanjih diskov in map za dokumente ter prenose
Patchwork dumped the login data database from \AppData\Local\Google\Chrome\User Data\Default\Login Data ... BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from /.mozilla/firefox/ for exfiltration.
A socket.io channel gives the actor interactive command execution, file upload and download, and clipboard access.
“The contract's call can return, among other things, a URL, a port number, an encryption key, a configuration... Once retrieved by the script, this information is used to send requests to the C2 server.”
začne komunikacijo, ki poteka preko TCP protokola. V tem primeru je naslov C2 strežnika sledeč: 173[.]211.106.101:1244
z njega prenese in izvrši nadaljnji tovor... prenese datoteki test.js ... in package.json ... nato pa še node test.js
331 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
147 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
the coding challenge is laced with malware and will trigger something nasty like InvisibleFerret, BeaverTail, OtterCookie, or one of the many other malware strains from our friends in boring Korea.
A malware family variant delivered through a smart contract in the UNC5342 campaign, with cryptocurrency theft as an objective.
A remote-access trojan delivered as a follow-on payload in the PolinRider chain, providing interactive command execution and persistence, including injection into developer applications.
Named malware mentioned in connection with the post, but only as a hashtag without further detail.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.