Skip to content

InvisibleFerret

InvisibleFerret is a Python-based cross-platform malware family associated with North Korea-linked developer-targeting campaigns including Contagious Interview, DeceptiveDevelopment, and activity tracked by some vendors as DEV#POPPER.

Profile source: Mallory opens in a new tab

InvisibleFerret

Family profile

InvisibleFerret is a Python-based cross-platform malware family associated with North Korea-linked developer-targeting campaigns including Contagious Interview, DeceptiveDevelopment, and activity tracked by some vendors as DEV#POPPER. It is commonly deployed after an initial JavaScript-stage loader such as BeaverTail or JADESNOW delivered through fake job interviews, trojanized coding challenges, malicious repositories, poisoned packages, or auto-executing development-environment artifacts. Reported delivery mechanisms include recruiter lures, malicious Visual Studio Code workspace tasks, Git hooks, npm package abuse, and other software supply-chain compromises aimed primarily at software developers, especially those involved in cryptocurrency, Web3, blockchain, and DeFi projects.

InvisibleFerret functions as both a backdoor and an infostealer. Across observed variants, it provides remote command execution, host profiling, file upload and download, browser process manipulation, theft of browser credentials and session cookies, collection of cryptocurrency wallet data, exfiltration of developer secrets such as SSH keys and environment-variable tokens, and theft of data from password managers and browser extensions. Windows-focused variants have included keylogging and clipboard capture. Some reporting also describes selective theft of cloud-service metadata and secrets stored in platform credential stores.

The malware is modular and heavily obfuscated, with multiple Python scripts used for staging, payload execution, browser theft, and auxiliary functions. It has been observed downloading additional components to extend capability, including modules for persistence, remote-access tooling, and browser-extension hijacking. Documented behaviors include establishing long-term access on compromised hosts, deploying remote administration software, modifying browser-related settings, and replacing or tampering with cryptocurrency wallet browser extensions to facilitate theft.

InvisibleFerret targets Windows, macOS, and Linux systems. It has been repeatedly linked to DPRK threat activity clusters including Lazarus-related operations and Famous Chollima or Wagemole-style fake interview campaigns. The malware is used for financially motivated theft, particularly cryptocurrency and credential theft, while also supporting broader post-compromise access and espionage objectives on high-value developer systems.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Session Hijacking

Reported operators

Threat actors

5 named in public reporting
Lazarus

What lands is a 77KB build of InvisibleFerret (also tracked as DEV#POPPER RAT), with a Python infostealer component assessed as OmniStealer.

Contagious Interview

It targets developers with fake job offers to deliver the JADESNOW loader and INVISIBLEFERRET backdoor.

CL-STA-0240

The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.

HexagonalRodent

The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.

TraderTraitor

The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.

MITRE ATT&CK

InvisibleFerret in ATT&CK

109 distinct techniques

Techniques

109 techniques
T1195 Supply Chain Compromise T1071 Application Layer Protocol T1555 Credentials from Password Stores T1195.001 Compromise Software Dependencies and Development Tools T1219 Remote Access Tools T1127.001 MSBuild T1543 Create or Modify System Process T1539 Steal Web Session Cookie T1041 Exfiltration Over C2 Channel T1059.007 JavaScript T1564.003 Hidden Window T1566.003 Spearphishing via Service T1105 Ingress Tool Transfer T1036 Masquerading T1056.001 Keylogging T1083 File and Directory Discovery T1027 Obfuscated Files or Information T1059 Command and Scripting Interpreter T1185 Browser Session Hijacking T1057 Process Discovery T1071.001 Web Protocols T1070.004 File Deletion T1005 Data from Local System T1566 Phishing T1571 Non-Standard Port T1106 Native API T1115 Clipboard Data T1048 Exfiltration Over Alternative Protocol T1059.006 Python T1219.002 Remote Desktop Software T1071.002 File Transfer Protocols T1518 Software Discovery T1195.002 Compromise Software Supply Chain T1129 Shared Modules T1649 Steal or Forge Authentication Certificates T1560 Archive Collected Data T1204.002 Malicious File T1566.002 Spearphishing Link T1583.001 Domains T1027.013 Encrypted/Encoded File T1025 Data from Removable Media T1614 System Location Discovery T1059.003 Windows Command Shell T1217 Browser Information Discovery T1082 System Information Discovery T1010 Application Window Discovery T1021.001 Remote Desktop Protocol T1657 Financial Theft T1555.001 Keychain T1567.004 Exfiltration Over Webhook T1030 Data Transfer Size Limits T1555.003 Credentials from Web Browsers T1552.001 Credentials In Files T1124 System Time Discovery T1095 Non-Application Layer Protocol T1133 External Remote Services T1016 System Network Configuration Discovery T1074.001 Local Data Staging T1119 Automated Collection T1560.002 Archive via Library T1140 Deobfuscate/Decode Files or Information T1056.002 GUI Input Capture T1021.004 SSH T1547.001 Registry Run Keys / Startup Folder T1543.001 Launch Agent T1037 Boot or Logon Initialization Scripts T1074 Data Staged T1033 System Owner/User Discovery T1189 Drive-by Compromise T1547.009 Shortcut Modification T1037.001 Logon Script (Windows) T1053 Scheduled Task/Job T1547 Boot or Logon Autostart Execution T1546.016 Installer Packages T1608.001 Upload Malware T1199 Trusted Relationship T1564 Hide Artifacts T1546 Event Triggered Execution T1059.004 Unix Shell T1497.001 System Checks T1656 Impersonation T1090.002 External Proxy T1586 Compromise Accounts T1587.001 Malware T1585 Establish Accounts T1059.005 Visual Basic T1564.001 Hidden Files and Directories T1204 User Execution T1598 Phishing for Information T1567 Exfiltration Over Web Service T1588.001 Malware T1053.005 Scheduled Task T1614.001 System Language Discovery T1566.001 Spearphishing Attachment T1589 Gather Victim Identity Information T1555.005 Password Managers T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol T1113 Screen Capture T1056 Input Capture T1547.013 XDG Autostart Entries T1489 Service Stop T1059.001 PowerShell T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol T1560.001 Archive via Utility T1679 Selective Exclusion T1087.001 Local Account T1020 Automated Exfiltration T1102 Web Service T1176 Software Extensions

Reporting

Research mentioning InvisibleFerret

Jul 24
Security Online Info

Contagious Interview Hides Malware in Coding Tests

Elastic Security Labs reported a Contagious Interview intrusion tied to a DPRK-aligned threat cluster after suspicious activity targeted Elastic’s community Slack workspace. Using a fake recruiter persona named Maxwell, the operator posted a fraudulent job opportunity and coding challenge that directed victims to trojanized Next.js e-commerce repositories. The malicious code hid payload components inside SVG image files using steganography, embedding Base64 fragments in flag images that were reassembled by serverValidation.js and executed with eval() when the local development server started. The campaign matches the broader Contagious Interview tradecraft tracked in MITRE ATT&CK as G1052, which relies on fake hiring outreach, code-repository lures, and social engineering to infect developers across Windows, macOS, and Linux. Elastic said the infection chain deployed a browser credential and crypto-wallet stealer, a file stealer, a persistent Socket.IO RAT, and a clipboard stealer capable of fetching Windows PE payloads, while code similarities to OTTERCOOKIE and infrastructure overlaps previously documented by JFrog reinforced the attribution. MITRE also associates the cluster with malware such as BeaverTail and InvisibleFerret, along with credential theft, financial theft, persistence through platform-specific startup mechanisms, and exfiltration over C2 and cloud or messaging services.

Jul 22
Cryptika

GolangGhost Steals Chrome Secrets From macOS Keychain and Hijacks MetaMask Permissions | Cryptika Cybersecurity

North Korean-linked threat actor Famous Chollima has been using fake job interviews and skill assessments to infect cryptocurrency and Web3 professionals with the PylangGhost and GolangGhost remote access trojans. Researchers said the operation impersonates firms including Coinbase, Robinhood, Uniswap, Archblock, and Parallel Studios, with lures delivered through LinkedIn, Discord, Telegram, email, and fraudulent interview sites. Victims are told to fix supposed camera or microphone problems by copying and pasting malicious commands, a ClickFix/ClickFake technique that installs malware on Windows and macOS systems; recent reporting said Linux was not targeted in the latest wave. The malware provides remote shell access, file transfer, system reconnaissance, persistence, and theft of browser credentials, cookies, and data from more than 80 browser extensions, including cryptocurrency wallets and password managers. Reporting indicates PylangGhost is a Python-based RAT functionally similar to GolangGhost, while GolangGhost on macOS can also deploy a SwiftUI credential harvester; both families use encrypted HTTP-based command-and-control communications. Investigators also described tailored fake assessment panels, invite-link validation, browser fingerprinting, mobile-device blocking, countdown timers, clipboard hijacking, and typosquatted infrastructure hosted largely through providers such as Hostinger and NameCheap, underscoring a financially motivated DPRK campaign aimed at stealing cryptocurrency and gaining access to company funds.

Jul 21
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Jul 20
Socradar

DPRK’s Famous Chollima Deploys RATs Through ClickFake Job Interviews

Jul 20
Cyber Security News

North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers

Jul 20
Gurucul Threat Research

New North Korean Campaign Uses Fake Coding Interviews to Steal Developer Credentials | Community Portal | Gurucul

Jul 18
Cyberveille

Campagne Contagious Interview : malware DPRK caché dans des SVG via stéganographie | CyberVeille

May 6
Opensourcemalware

Lazarus Group Using Git Hooks To Hide Malware | OpenSource Malware Blog

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.