InvisibleFerret is a malware family tracked across 11 threat clusters and 13 intelligence report mentions on ThreatCluster. First observed November 14, 2025; most recent activity May 26, 2026.
The Google Threat Intelligence Group (GTIG) reports that North Korean threat actor UNC5342 has adopted a new technique called EtherHiding to deliver malware and facilitate cryptocurrency theft. This method embeds…
Void Dokkaebi, a North Korean threat actor, has escalated its malware distribution tactics by using fake job interviews to compromise software developers. This campaign, known as the 'Contagious Interview,' targets…
The North Korea-linked threat group Void Dokkaebi has enhanced its InvisibleFerret malware by converting it from readable Python scripts to compiled binary modules (.pyd and .so files). This upgrade makes it more…
Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…
Research indicates that Russian APT group Gamaredon and North Korean Lazarus Group are collaborating by sharing operational infrastructure. This partnership marks a significant development in state-sponsored cyber…
North Korea's Lazarus Group and Russia's Gamaredon have reportedly begun collaborating in cyber operations, marking the first known instance of such cooperation. Researchers from Gen Digital indicate that the two groups…
The financial sector, including banks and cryptocurrency platforms, is facing a complex cyber threat landscape. This sector's heavy reliance on digital infrastructure makes it a prime target for both financially…
North Korean threat actors are utilizing JSON storage services to distribute malware through the Contagious Interview campaign, which has been active since 2023. They impersonate hiring professionals to lure developers…
The ClickFix malware has evolved to utilize videos, timers, and OS-specific tricks to deceive users into self-infection. This campaign leverages social engineering tactics to manipulate victims into executing malicious…
A new wave of ClickFix attacks is utilizing fake Windows Update screens to deceive users into executing malicious commands that install infostealing malware. These attacks employ steganography to hide malware within PNG…