InvisibleFerret is a Python-based cross-platform malware family associated with North Korea-linked developer-targeting intrusion activity, including the Contagious Interview and related clusters tracked under names such as Famous Chollima, DeceptiveDevelopment, DEV#POPPER, and Void Dokkaebi. It is commonly deployed after an initial BeaverTail or similar loader stage delivered through fake recruiter lures, trojanized coding challenges, malicious repositories, npm packages, Visual Studio Code task abuse, Git hooks, fake conferencing or interview fixes, and other developer workflow compromises.
InvisibleFerret functions primarily as a backdoor with substantial infostealing capability. Reported behavior includes remote command execution, host profiling, browser credential theft, browser cookie and session theft, theft of cryptocurrency wallet data, collection of developer secrets and environment-variable tokens, theft of SSH keys and cloud-related credentials, file discovery and upload, and staged data collection prior to exfiltration. Multiple reports also describe Windows-focused keylogging and clipboard capture, including theft or hijacking of cryptocurrency-related clipboard contents. Some variants target browser extensions and wallet extensions directly, and newer variants have been observed modifying browser preferences or replacing wallet-related extensions to facilitate credential and wallet theft.
The malware is modular and has been described as comprising multiple Python scripts or components, including downloader, backdoor, browser-stealer, keylogging, and remote-access modules. It uses heavy obfuscation in script-based forms, and later variants were compiled with Cython or distributed as native extension modules on Windows and macOS to hinder analysis and evade script-focused defenses. Command-and-control has been reported over TCP, HTTP, and Socket.IO-style channels depending on variant and campaign. Some versions also support alternate exfiltration paths such as FTP or Telegram.
Persistence varies by campaign and version. Several reports describe Windows persistence through startup or scheduled-task mechanisms and macOS persistence through LaunchAgents. Some variants also deploy remote administration software such as AnyDesk to maintain attacker access. The malware has been used chiefly against software developers, especially those involved in cryptocurrency, blockchain, DeFi, and Web3 projects, but related campaigns have also targeted business and non-technical personnel in the same ecosystem. Its operational purpose is strongly aligned with credential theft, cryptocurrency theft, and sustained post-compromise access, with some reporting also assessing an espionage objective for higher-value victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It's the same Contagious Interview social engineering — fake recruiter, "coding assessment" repo, multi-stage loader pulling InvisibleFerret-style implants for crypto wallet and credential theft...
It targets developers with fake job offers to deliver the JADESNOW loader and INVISIBLEFERRET backdoor.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
PolinRider is a DPRK-linked supply-chain campaign... takes over legitimate GitHub accounts and quietly injects an obfuscated JavaScript loader into repositories the maintainer already owns.
runOptions의 runOn 옵션이 folderOpen으로 설정되어 있어 레포지토리에 대한 폴더가 VSCode에서 열릴 경우 자동으로 삽입된 명령어가 실행되는 방식이다.
Malicious npm package posing as a Tailwind utility; functional decoy in index.ts
The starting point of the attack is a hidden Microsoft Visual Studio Code (VS Code) task named "eslint-check" that's configured with the "runOn: 'folderOpen'" option to trigger the execution of arbitrary code when the folder is opened as a workspace folder in an IDE like VS Code or Cursor.
OS 、ブラウザで保有している認証情報やブラウザ拡張機能としてインストールされている暗号資産ウォレット関連ファイルも窃取し、 C2 サーバへアップロードします。
It's also equipped to harvest developer-oriented information like Git credentials, GitHub CLI hosts.yml, GitHub Desktop logs, VS Code, and global storage, as well as data from Windows Credential Manager, Linux Secret Service, KDE Wallet, macOS Keychain...
InvisibleFerret implant (also reported as DEV#POPPER RAT and OmniStealer) for credential theft, browser-data theft, wallet exfiltration, and socket.io-based C2.
hxxp://[악성코드 다운로드용 C&C 서버]:1244/key ... /j/[캠페인 ID] 에서 Beavertail 다운로드 ... /uploads 로 업로드한다.
For FTP uploads, the C&C server provides the domain, username, and password.
The loader still resolves its second stage from blockchain dead-drops across TRON, Aptos, and BNB Smart Chain, decrypts it with embedded XOR keys, and runs it through eval().
273 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
135 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another DPRK-linked malware family used as a comparison for the actors' shift toward compiled binaries for stealth.
Referenced only as an additional artifact family defenders should check for on Windows systems during incident response.
A Lazarus implant used for credential theft, browser-data theft, wallet exfiltration, and socket.io-based command-and-control.
Python malware composed of multiple scripts. It provides backdoor capability over sockets, supports command execution, self-deletion, keylogging and clipboard logging, file upload and FTP exfiltration, dead-drop/payload retrieval, AnyDesk deployment for remote access, and browser/crypto-wallet manipulation including replacement of MetaMask and Rabby Wallet extensions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.