Skip to content
ThreatCluster

Void Dokkaebi Upgrades InvisibleFerret Malware to Evade Detection

First seen 25 May 2026, 20:31 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 26, 2026 at 20:10 UTC
  • Void Dokkaebi has upgraded InvisibleFerret malware to compiled binary formats.
  • The new .pyd and .so file formats evade traditional detection methods.
  • Organizations using signature-based tools are at increased risk from this malware.

The North Korea-linked threat group Void Dokkaebi has enhanced its InvisibleFerret malware by converting it from readable Python scripts to compiled binary modules (.pyd and .so files). This upgrade makes it more challenging for security tools to detect the malware through traditional static analysis methods. Previously, InvisibleFerret was easier to identify due to its script format, but the new delivery method leverages Cython to compile the code, increasing its stealth capabilities. The malware is primarily used for information theft and poses a significant risk to organizations that rely on signature-based detection methods. The campaign marks a notable evolution in the group's tactics, indicating a shift towards more sophisticated malware delivery mechanisms. Security professionals are advised to be vigilant and update their detection capabilities accordingly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 107d ago How this analysis works

Timeline

2026-05-25
InvisibleFerret malware upgrade announced
Void Dokkaebi has repackaged InvisibleFerret into .pyd and .so files, enhancing evasion techniques.
Gbhackers
2026-05-25
Cybersecurity implications discussed
Experts warn that the new format makes it harder for security software to detect the malware.
Cybersecuritynews

More articles in this cluster (2)

Following this threat?

Track FAMOUS CHOLLIMA and InvisibleFerret in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed