Lazarus 그룹의 InvisibleFerret 악성코드

2024-10-14 Hauri ( Document No : DT-20241014-001 )

https://hauri.co.kr/security/security_view.html?intSeq=69&page=1&keyfield=&key=

Attachments

2024-10-14ììëìë³ê³ìLazarusêë¹ìInvisibleFerretììì½ë_1rHxRSQ.pdf (1 MB)

Thumbnail for Lazarus 그룹의 InvisibleFerret 악성코드

Hauri reports that Lazarus is distributing InvisibleFerret malware through job-task lures aimed at job seekers, continuing to abuse GitHub repositories while changing obfuscation methods and adding keylogging capability. The analyzed downloader retrieves and executes Backdoor, InfoStealer, and Keylogger components, attempts to install missing Python dependencies, and supports Windows and Linux payload execution while handling macOS differently. The activity aligns with DPRK Contagious Interview-style operations in which fake hiring workflows deliver cross-platform malware to collect credentials, browser data, and other victim information.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 95.164.17.24 2024-07-15 2026-04-01
DOMAIN ip-api.com 2022-11-14 2026-01-21
URL http://ip-api.com/json 2024-07-31 2026-01-20
IPv4 95.164.7.171 2024-10-14 2025-07-26
HASH d1a2ee0fc37380a451584f9e5edd3dd7 2024-10-14 2024-10-14
HASH 40a81385f7565ee02b3a13de4513b2f… 2024-10-14 2024-10-14
HASH c933aec60fbd4e8b946025d718afaed9 2024-10-14 2024-10-14
HASH 9e3d339ba3f1b0bb2647d6b961b0790… 2024-10-14 2024-10-14

Related Actors

Related Reports

« Back