InvisibleFerret Malware: Technical Analysis
2025-01-21 • Any Run •
https://any.run/cybersecurity-blog/invisibleferret-malware-analysis/
ANY.RUN analyzes InvisibleFerret, a Python malware used in North Korean job-interview campaigns known as Contagious Interview or DevPopper. The campaign targets developers in technology, finance, and cryptocurrency sectors by posing as hiring workflows and delivering malware as coding challenges, dependencies, or fake video-call software. BeaverTail acts as the JavaScript stealer and loader, then downloads a portable Python environment and deploys InvisibleFerret as a later stage. InvisibleFerret profiles the host, contacts C2 on unusual ports, uses FTP and SSH-style upload routines for exfiltration, targets documents, downloads, browser data, and other files, can run attacker commands, and may install AnyDesk for remote access.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 147.124.214.129 | 2024-05-10 | 2026-02-03 |
| DOMAIN | ip-api.com | 2022-11-14 | 2026-01-21 |
| HASH | 6a104f07ab6c5711b6bc8bf6ff956ab… | 2024-10-23 | 2025-07-26 |
| IPv4 | 173.211.106.101 | 2024-04-25 | 2025-07-26 |
| HASH | 47830f7007b4317dc8ce1b16f3ae79f… | 2025-01-21 | 2025-01-21 |