What lands is a 77KB build of InvisibleFerret (also tracked as DEV#POPPER RAT), with a Python infostealer component assessed as OmniStealer.
InvisibleFerret
InvisibleFerret is a Python-based cross-platform malware family associated with North Korea-linked developer-targeting campaigns including Contagious Interview, DeceptiveDevelopment, and activity tracked by some vendors as DEV#POPPER.
Profile source: Mallory opens in a new tabInvisibleFerret
Family profile
InvisibleFerret is a Python-based cross-platform malware family associated with North Korea-linked developer-targeting campaigns including Contagious Interview, DeceptiveDevelopment, and activity tracked by some vendors as DEV#POPPER. It is commonly deployed after an initial JavaScript-stage loader such as BeaverTail or JADESNOW delivered through fake job interviews, trojanized coding challenges, malicious repositories, poisoned packages, or auto-executing development-environment artifacts. Reported delivery mechanisms include recruiter lures, malicious Visual Studio Code workspace tasks, Git hooks, npm package abuse, and other software supply-chain compromises aimed primarily at software developers, especially those involved in cryptocurrency, Web3, blockchain, and DeFi projects.
InvisibleFerret functions as both a backdoor and an infostealer. Across observed variants, it provides remote command execution, host profiling, file upload and download, browser process manipulation, theft of browser credentials and session cookies, collection of cryptocurrency wallet data, exfiltration of developer secrets such as SSH keys and environment-variable tokens, and theft of data from password managers and browser extensions. Windows-focused variants have included keylogging and clipboard capture. Some reporting also describes selective theft of cloud-service metadata and secrets stored in platform credential stores.
The malware is modular and heavily obfuscated, with multiple Python scripts used for staging, payload execution, browser theft, and auxiliary functions. It has been observed downloading additional components to extend capability, including modules for persistence, remote-access tooling, and browser-extension hijacking. Documented behaviors include establishing long-term access on compromised hosts, deploying remote administration software, modifying browser-related settings, and replacing or tampering with cryptocurrency wallet browser extensions to facilitate theft.
InvisibleFerret targets Windows, macOS, and Linux systems. It has been repeatedly linked to DPRK threat activity clusters including Lazarus-related operations and Famous Chollima or Wagemole-style fake interview campaigns. The malware is used for financially motivated theft, particularly cryptocurrency and credential theft, while also supporting broader post-compromise access and espionage objectives on high-value developer systems.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Keylogging
- Lateral Movement
- Persistence
- Post Exploitation
- Session Hijacking
Reported operators
Threat actors
5 named in public reportingIt targets developers with fake job offers to deliver the JADESNOW loader and INVISIBLEFERRET backdoor.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
MITRE ATT&CK
InvisibleFerret in ATT&CK
109 distinct techniquesTechniques
109 techniquesReporting
Research mentioning InvisibleFerret
Contagious Interview Hides Malware in Coding Tests
Elastic Security Labs reported a Contagious Interview intrusion tied to a DPRK-aligned threat cluster after suspicious activity targeted Elastic’s community Slack workspace. Using a fake recruiter persona named Maxwell, the operator posted a fraudulent job opportunity and coding challenge that directed victims to trojanized Next.js e-commerce repositories. The malicious code hid payload components inside SVG image files using steganography, embedding Base64 fragments in flag images that were reassembled by serverValidation.js and executed with eval() when the local development server started. The campaign matches the broader Contagious Interview tradecraft tracked in MITRE ATT&CK as G1052, which relies on fake hiring outreach, code-repository lures, and social engineering to infect developers across Windows, macOS, and Linux. Elastic said the infection chain deployed a browser credential and crypto-wallet stealer, a file stealer, a persistent Socket.IO RAT, and a clipboard stealer capable of fetching Windows PE payloads, while code similarities to OTTERCOOKIE and infrastructure overlaps previously documented by JFrog reinforced the attribution. MITRE also associates the cluster with malware such as BeaverTail and InvisibleFerret, along with credential theft, financial theft, persistence through platform-specific startup mechanisms, and exfiltration over C2 and cloud or messaging services.
GolangGhost Steals Chrome Secrets From macOS Keychain and Hijacks MetaMask Permissions | Cryptika Cybersecurity
North Korean-linked threat actor Famous Chollima has been using fake job interviews and skill assessments to infect cryptocurrency and Web3 professionals with the PylangGhost and GolangGhost remote access trojans. Researchers said the operation impersonates firms including Coinbase, Robinhood, Uniswap, Archblock, and Parallel Studios, with lures delivered through LinkedIn, Discord, Telegram, email, and fraudulent interview sites. Victims are told to fix supposed camera or microphone problems by copying and pasting malicious commands, a ClickFix/ClickFake technique that installs malware on Windows and macOS systems; recent reporting said Linux was not targeted in the latest wave. The malware provides remote shell access, file transfer, system reconnaissance, persistence, and theft of browser credentials, cookies, and data from more than 80 browser extensions, including cryptocurrency wallets and password managers. Reporting indicates PylangGhost is a Python-based RAT functionally similar to GolangGhost, while GolangGhost on macOS can also deploy a SwiftUI credential harvester; both families use encrypted HTTP-based command-and-control communications. Investigators also described tailored fake assessment panels, invite-link validation, browser fingerprinting, mobile-device blocking, countdown timers, clipboard hijacking, and typosquatted infrastructure hosted largely through providers such as Hostinger and NameCheap, underscoring a financially motivated DPRK campaign aimed at stealing cryptocurrency and gaining access to company funds.