Skip to content

InvisibleFerret Malware Uses .pyd and .so Files to Evade Script Detection

Gbhackers Mayura Kathir May 25, 2026

A North Korea-linked threat group, Void Dokkaebi, also known as Famous Chollima, has significantly upgraded its malware delivery techniques by converting its Python-based InvisibleFerret malware into compiled binary modules. InvisibleFerret was previously deployed as readable Python scripts, making it easier for defenders to detect through static analysis and signature-based tools. The latest campaign leverages Cython, […]

Extracted Entities

Attack Types (1)

Countries (1)

Malware (1)

Platforms (1)