Void Dokkaebi Upgrades InvisibleFerret Malware to Evade Detection
Article Content
- •Void Dokkaebi has upgraded InvisibleFerret malware to compiled binary formats.
- •The new .pyd and .so file formats evade traditional detection methods.
- •Organizations using signature-based tools are at increased risk from this malware.
The North Korea-linked threat group Void Dokkaebi has enhanced its InvisibleFerret malware by converting it from readable Python scripts to compiled binary modules (.pyd and .so files). This upgrade makes it more challenging for security tools to detect the malware through traditional static analysis methods. Previously, InvisibleFerret was easier to identify due to its script format, but the new delivery method leverages Cython to compile the code, increasing its stealth capabilities. The malware is primarily used for information theft and poses a significant risk to organizations that rely on signature-based detection methods. The campaign marks a notable evolution in the group's tactics, indicating a shift towards more sophisticated malware delivery mechanisms. Security professionals are advised to be vigilant and update their detection capabilities accordingly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track FAMOUS CHOLLIMA and InvisibleFerret in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Social Engineering Campaign Hijacks Microsoft 365 Accounts via Passkey Alerts A social engineering campaign impersonating IT support staff is actively hijacking Microsoft 365 accounts. The attackers use passkey-themed lures to trick users into providing credentials, leading to unauthorized access and data exfiltration. Microsoft Security Research has tracked these intrusions since May 2026…