InvisibleFerret is a Python-based modular malware family and cross-platform backdoor/RAT with information-stealing capabilities. It is closely associated with DPRK-linked activity clusters including Lazarus-related operations, Contagious Interview, DeceptiveDevelopment, Famous Chollima, PurpleBravo, and DEV#POPPER reporting. It is commonly delivered as a later stage by BeaverTail, including in fake job-interview and developer-targeting campaigns, malicious VS Code repositories using folder-open tasks, trojanized coding challenges, malicious npm/package ecosystem compromises, and fake recruiter lures. Reported delivery chains include BeaverTail downloading InvisibleFerret from hxxp://66.235.175[.]117:1244/client/knHbMe8 as a .npl file and executing it via Python; on Windows, BeaverTail may also download Python to run the payload. Some reporting states it targets developers with fake job offers and may be delivered after JADESNOW in EtherHiding-enabled chains.
The malware is described as being composed of multiple Python scripts, with reporting variously describing four or five components/modules. It has been observed protected by layered obfuscation using techniques including Base85, XOR, Base64, zlib, reversed Base64, and repeated exec execution. Newer variants reportedly migrated from readable Python scripts to compiled binaries, distributed as .pyd files on Windows and .so components on macOS, launched by lightweight Python runtime scripts.
Capabilities directly described in the content include remote control of compromised hosts, command execution, reverse shell/backdoor functionality, credential theft, browser-data theft, browser credential and session-cookie theft, wallet exfiltration, theft of SSH private keys, theft of environment-variable secrets such as AWS, GCP, npm, and GitHub tokens, collection of .env files, and theft of developer artifacts. It targets browser and wallet data across platforms and has been reported stealing saved logins, autofill and payment-card data from Chromium-based browsers, Firefox data, password-manager data, cloud-storage metadata, and cryptocurrency wallet/browser-extension data including MetaMask, Rabby Wallet, Coinbase Wallet, Phantom, and others. On Windows, reported functions include keylogging, clipboard capture/theft, and browser-focused keylogging/clipboard theft modules. The malware can stage collected data in consolidated folders prior to exfiltration, compress data into ZIP archives, upload files to C2, and in some variants exfiltrate via Telegram and FTP in addition to HTTP/socket-based channels.
Observed components and behaviors include a launcher/downloader that retrieves additional payloads such as pay and bow from hxxp://66.235.175[.]117:1244; a pay backdoor connecting to 216.250.251[.]87:1245 and supporting shell execution, self-destruction, keylogging, clipboard theft, file upload, browser termination, recursive file theft, archive-and-exfiltrate actions, and downloading additional payloads; an adc component that downloads and configures AnyDesk for attacker remote access; and an mc component that replaces legitimate MetaMask and Rabby Wallet browser extensions with malicious versions from hxxp://45.59.163[.]55:1244/mmz/[Extension ID]_knHbMe8, exfiltrates Chrome profile data to hxxp://45.59.163[.]55:1244/h, modifies Chrome Secure Preferences, and on macOS may overwrite /Applications/Google Chrome.app to downgrade Chrome 140 or later. Reporting also describes a browser-stealer component named bow and a Windows-focused keylogger/clipboard module named mlip in some variants.
Persistence is inconsistently described across sources, but high-confidence reporting in the content states that InvisibleFerret has established persistence on macOS using LaunchAgents with the file name com.avatar.update.wake.plist, and on Windows via a bow component that drops an obfuscated TsunamiInjector payload into the Startup folder. TsunamiInjector is described as decrypting roughly 1,000 Pastebin URLs, retrieving another payload, downloading Runtime Broker.exe into %APPDATA%\Microsoft\Windows\Applications\, adding a Windows Defender exclusion, and creating a scheduled task for execution at user login. Other reporting also describes AnyDesk deployment for persistent remote access.
Command-and-control and exfiltration methods mentioned in the content include socket.io-based C2, TCP/JSON communications, HTTP communications including exfiltration to the /Uploads or /uploads URI, and connections to 216.250.251[.]87:1245. The malware has been described as a persistent backdoor for high-value targets, enabling long-term espionage, data theft, and possible lateral movement within a network. Targeting in the content is heavily focused on software developers, especially Web3, blockchain, DeFi, and cryptocurrency-related personnel and organizations across Windows, macOS, and Linux environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The unpacked chain is the familiar Lazarus toolkit: a Beavertail loader that fingerprints the host OS and selects an InvisibleFerret implant (also reported as DEV#POPPER RAT and OmniStealer) for credential theft, browser-data theft, wallet exfiltration, and socket.io-based C2.
InvisibleFerret は、 Python で開発されているマルウェアで、複数の Python スクリプトで構成されています。 ダウンローダ バックドア ブラウザ情報を窃取するスティーラー キーロガー
It targets developers with fake job offers to deliver the JADESNOW loader and INVISIBLEFERRET backdoor.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The malware is designed to download additional payloads, including a cross-platform Python backdoor codenamed InvisibleFerret.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
PolinRider is a DPRK-linked supply-chain campaign... takes over legitimate GitHub accounts and quietly injects an obfuscated JavaScript loader into repositories the maintainer already owns.
runOptions의 runOn 옵션이 folderOpen으로 설정되어 있어 레포지토리에 대한 폴더가 VSCode에서 열릴 경우 자동으로 삽입된 명령어가 실행되는 방식이다.
Malicious npm package posing as a Tailwind utility; functional decoy in index.ts
The starting point of the attack is a hidden Microsoft Visual Studio Code (VS Code) task named "eslint-check" that's configured with the "runOn: 'folderOpen'" option to trigger the execution of arbitrary code when the folder is opened as a workspace folder in an IDE like VS Code or Cursor.
OS 、ブラウザで保有している認証情報やブラウザ拡張機能としてインストールされている暗号資産ウォレット関連ファイルも窃取し、 C2 サーバへアップロードします。
It's also equipped to harvest developer-oriented information like Git credentials, GitHub CLI hosts.yml, GitHub Desktop logs, VS Code, and global storage, as well as data from Windows Credential Manager, Linux Secret Service, KDE Wallet, macOS Keychain...
InvisibleFerret implant (also reported as DEV#POPPER RAT and OmniStealer) for credential theft, browser-data theft, wallet exfiltration, and socket.io-based C2.
hxxp://[악성코드 다운로드용 C&C 서버]:1244/key ... /j/[캠페인 ID] 에서 Beavertail 다운로드 ... /uploads 로 업로드한다.
For FTP uploads, the C&C server provides the domain, username, and password.
The loader still resolves its second stage from blockchain dead-drops across TRON, Aptos, and BNB Smart Chain, decrypts it with embedded XOR keys, and runs it through eval().
273 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
132 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Lazarus implant used for credential theft, browser-data theft, wallet exfiltration, and socket.io-based command-and-control.
Python malware composed of multiple scripts. It provides backdoor capability over sockets, supports command execution, self-deletion, keylogging and clipboard logging, file upload and FTP exfiltration, dead-drop/payload retrieval, AnyDesk deployment for remote access, and browser/crypto-wallet manipulation including replacement of MetaMask and Rabby Wallet extensions.
Python-based malware composed of multiple scripts. It provides backdoor access, executes commands, uploads files, performs keylogging and clipboard theft, can deploy additional payloads, establish persistence, install remote access software, and replace legitimate crypto wallet browser extensions with malicious versions.
A Python-based backdoor and infostealer delivered via malicious npm and Go packages. It steals browser credentials, cryptocurrency wallets, developer artifacts, and OS credential-store data, while also enabling persistent remote access and data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.