Lazarus 그룹의 InvisibleFerret 악성코드
2024-10-14 • Hauri • ( Document No : DT-20241014-001 ) •
https://hauri.co.kr/security/security_view.html?intSeq=69&page=1&keyfield=&key=
Attachments
Hauri reports that Lazarus is distributing InvisibleFerret malware through job-task lures aimed at job seekers, continuing to abuse GitHub repositories while changing obfuscation methods and adding keylogging capability. The analyzed downloader retrieves and executes Backdoor, InfoStealer, and Keylogger components, attempts to install missing Python dependencies, and supports Windows and Linux payload execution while handling macOS differently. The activity aligns with DPRK Contagious Interview-style operations in which fake hiring workflows deliver cross-platform malware to collect credentials, browser data, and other victim information.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 95.164.17.24 | 2024-07-15 | 2026-04-01 |
| DOMAIN | ip-api.com | 2022-11-14 | 2026-01-21 |
| URL | http://ip-api.com/json | 2024-07-31 | 2026-01-20 |
| IPv4 | 95.164.7.171 | 2024-10-14 | 2025-07-26 |
| HASH | d1a2ee0fc37380a451584f9e5edd3dd7 | 2024-10-14 | 2024-10-14 |
| HASH | defe30d5091810c856ed1f28d7d7e5be | 2024-10-14 | 2024-10-14 |
| HASH | c933aec60fbd4e8b946025d718afaed9 | 2024-10-14 | 2024-10-14 |
| HASH | 1f7300095455c1aec937efbb974021d0 | 2024-10-14 | 2024-10-14 |