#InvisibleFerret

Malware/Tool

2023-11-21 • Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors

InvisibleFerret is a cross-platform Python remote-access Trojan deployed in DPRK-linked Contagious Interview campaigns, commonly after the BeaverTail stealer. Malicious coding projects, npm packages, and blockchain-resolved loaders have delivered it to developer systems. Reported capabilities include remote command execution, file and directory theft, browser credentials and session cookies, SSH keys, cloud and source-control tokens, cryptocurrency-wallet data, and, on Windows, keylogging and clipboard capture. Some versions use the /client/<id> command-and-control pattern and establish persistence. MITRE ATT&CK S1245.

Tagged Reports

« Back