Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware

2026-05-22 Trend Micro

https://www.trendmicro.com/en_us/research/26/e/analyzing-void-dokkaebi-invisibleferret-malware.html

Thumbnail for Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware

Trend Micro reports that Void Dokkaebi, also known as Famous Chollima, has migrated InvisibleFerret from readable Python scripts into Cython-compiled `.pyd` modules on Windows and `.so` modules on macOS. The campaign remains focused on software developers and cryptocurrency-related environments, with capabilities including backdoor access, browser credential theft, clipboard monitoring, keylogging, cryptocurrency wallet targeting, and trojanized wallet-extension installation. BeaverTail now functions as a broader multistage component, using obfuscation, downloader and backdoor modules, wallet and browser stealers, and Chrome/Brave extension trojanization for MetaMask, Coinbase Wallet, Phantom, and related targets. The shift to Cython complicates script-only detection and can hide or defer infrastructure details because runtime loader scripts may provide IP addresses and ports to the compiled modules.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 45.59.160.199 2026-05-22 2026-05-22

Related Actors

Related Reports

« Back