216.73.217.22

InvisibleFerret Malware: Technical Analysis

· Published 21/01/2025 22:17 · Modified 22/01/2025 09:16

Export JSON

Essential information

Published
21/01/2025 22:17
Modified
22/01/2025 09:16
Tags
2025-01-21 beavertail invisibleferret qrlog rustdoor stealer
Related entities
4 observables, 1 intrusion sets (apt), 14 techniques (mitre), 5 malware, 2 others

Description

A recent surge in North Korean activity involves fake job interviews to distribute malware, including . This Python-based malware targets the technology, finance, and cryptocurrency sectors, focusing on developers. It steals source code, wallets, and sensitive files. gathers victim information, exfiltrates browser data, and implements keylogging and clipboard monitoring. The malware uses FTP and Telegram for data exfiltration, and AnyDesk for persistence. It targets major browsers and specific extensions, particularly crypto wallets and authentication apps. The analysis reveals poor coding practices and weak obfuscation techniques. The campaign, known as Contagious Interview or DevPopper, demonstrates significant investment in infrastructure and social engineering tactics.

External references