InvisibleFerret Malware: Technical Analysis

2025-01-21 Any Run

https://any.run/cybersecurity-blog/invisibleferret-malware-analysis/

Thumbnail for InvisibleFerret Malware: Technical Analysis

ANY.RUN analyzes InvisibleFerret, a Python malware used in North Korean job-interview campaigns known as Contagious Interview or DevPopper. The campaign targets developers in technology, finance, and cryptocurrency sectors by posing as hiring workflows and delivering malware as coding challenges, dependencies, or fake video-call software. BeaverTail acts as the JavaScript stealer and loader, then downloads a portable Python environment and deploys InvisibleFerret as a later stage. InvisibleFerret profiles the host, contacts C2 on unusual ports, uses FTP and SSH-style upload routines for exfiltration, targets documents, downloads, browser data, and other files, can run attacker commands, and may install AnyDesk for remote access.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 147.124.214.129 2024-05-10 2026-02-03
DOMAIN ip-api.com 2022-11-14 2026-01-21
HASH 6a104f07ab6c5711b6bc8bf6ff956ab… 2024-10-23 2025-07-26
IPv4 173.211.106.101 2024-04-25 2025-07-26
HASH 47830f7007b4317dc8ce1b16f3ae79f… 2025-01-21 2025-01-21

Related Reports

2025-02-20 • 76% Match
#BeaverTail #InvisibleFerret #DeceptiveDevelopment #T1027.013 #T1082 #T1119 #T1059.003 #T1140 #T1005 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1115 #T1083 #T1056.001 #T1059.006 #T1059.007 #T1204.002 #T1566.003 #T1555.003 #T1124 #T1583.003 #T1552.001 #T1585.001 #T1219 #T1133 #T1571 #T1564.001 #T1016 #T1074.001 #T1657 #T1071.002 #T1021.001 #T1614 #T1555.001 #T1217 #T1095 #T1025 #T1010 #T1560.002 #T1030 #T1567.004 #T1564.003
Shares tags: BeaverTail, InvisibleFerret, T1571 • Shares 2 IOCs • Published within a month
« Back