Lazarus 그룹의 InvisibleFerret 악성코드

2024-10-14 Hauri ( Document No : DT-20241014-001 )

https://hauri.co.kr/security/security_view.html?intSeq=69&page=1&keyfield=&key=

Attachments

2024-10-14ììëìë³ê³ìLazarusêë¹ìInvisibleFerretììì½ë_1rHxRSQ.pdf (1 MB)

Thumbnail for Lazarus 그룹의 InvisibleFerret 악성코드

Hauri reports that Lazarus is distributing InvisibleFerret malware through job-task lures aimed at job seekers, continuing to abuse GitHub repositories while changing obfuscation methods and adding keylogging capability. The analyzed downloader retrieves and executes Backdoor, InfoStealer, and Keylogger components, attempts to install missing Python dependencies, and supports Windows and Linux payload execution while handling macOS differently. The activity aligns with DPRK Contagious Interview-style operations in which fake hiring workflows deliver cross-platform malware to collect credentials, browser data, and other victim information.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 95.164.17.24 2024-07-15 2026-04-01
DOMAIN ip-api.com 2022-11-14 2026-01-21
URL http://ip-api.com/json 2024-07-31 2026-01-20
IPv4 95.164.7.171 2024-10-14 2025-07-26
HASH d1a2ee0fc37380a451584f9e5edd3dd7 2024-10-14 2024-10-14
HASH defe30d5091810c856ed1f28d7d7e5be 2024-10-14 2024-10-14
HASH c933aec60fbd4e8b946025d718afaed9 2024-10-14 2024-10-14
HASH 1f7300095455c1aec937efbb974021d0 2024-10-14 2024-10-14

Related Actors

Related Reports

« Back