Description
InvisibleFerret is a modular Python malware that provides data exfiltration and remote access capabilities on infected systems. It consists of main, payload, browser, and AnyDesk modules, and North Korea affiliated threat actors have used it as part of the Contagious Interview campaign against job seekers.
Stats
- First seen
- August 2024
- Last seen
- September 2026
Also known as
Invisibleferret
MITRE ATT&CK techniques
35 techniques across 9 tactics.
TA0003 Persistence
TA0005 Stealth
TA0006 Credential Access
TA0007 Discovery
TA0009 Collection
TA0011 Command and Control
TA0010 Exfiltration
Associated groups
Alert name variants
| Alert Name |
|---|
| Gen:Variant.InvisibleFerret.1 |
| Gen:Variant.InvisibleFerret.6 |
| Gen:Variant.InvisibleFerret.8 |
| MacOS.Spyware.InvisibleFerret |
| Script-Python.Backdoor.Invisibleferret |
| Script-Python.Backdoor.InvisibleFerret |
| Script-Python.Downloader.InvisibleFerret |
| Script-Python.Spyware.InvisibleFerret |
| Script-Python.Trojan.Invisibleferret |
| Script-Python.Trojan.InvisibleFerret |