Netskope Threat Labs

InvisibleFerret

ATP Sandbox Adv. HeuristicsAV

InvisibleFerret is a modular Python malware that provides data exfiltration and remote access capabilities on infected systems. It consists of main, payload, browser, and AnyDesk modules, and North Korea affiliated threat actors have used it as part of the Contagious Interview campaign against job seekers.

First seen
August 2024
Last seen
September 2026
Invisibleferret

35 techniques across 9 tactics.

TA0002 Execution

TA0003 Persistence

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1087Account Discovery
  • T1518Software Discovery
  • T1614System Location Discovery

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel
  • T1048Exfiltration Over Alternative Protocol
    • T1048.003Exfiltration Over Unencrypted Non-C2 Protocol
  • T1567Exfiltration Over Web Service

TA0040 Impact

Alert Name
Gen:Variant.InvisibleFerret.1
Gen:Variant.InvisibleFerret.6
Gen:Variant.InvisibleFerret.8
MacOS.Spyware.InvisibleFerret
Script-Python.Backdoor.Invisibleferret
Script-Python.Backdoor.InvisibleFerret
Script-Python.Downloader.InvisibleFerret
Script-Python.Spyware.InvisibleFerret
Script-Python.Trojan.Invisibleferret
Script-Python.Trojan.InvisibleFerret