ATT&CKSoftwareInvisibleFerret

InvisibleFerret

S1245

Malware.View on attack.mitre.org

About this malware

InvisibleFerret is a modular python malware that is leveraged for data exfiltration and remote access capabilities. InvisibleFerret consists of four modules: main, payload, browser, and AnyDesk. InvisibleFerret malware has been leveraged by North Korea-affiliated threat actors identified as DeceptiveDevelopment or Contagious Interview since 2023. InvisibleFerret has historically been introduced to the victim environment through the use of the BeaverTail malware.

Techniques used35

Procedure examples35

TechniqueProcedure example
T1005
Data from Local System

InvisibleFerret has collected data utilizing a script that contained a list of excluded files and directory names and naming patterns of interest such as environment and configuration files, documents, spreadsheets, and other files that contained the words secret, wallet, private, and password.

T1016
System Network Configuration Discovery

InvisibleFerret has collected the local IP address, and external IP.

T1027.013
Encrypted/Encoded File

InvisibleFerret has utilized the XOR and Base64 encoding for each of its modules. InvisibleFerret has also obfuscated files with a combination of zlib, Base64 and reverse string order. InvisibleFerret has also utilized the XOR and Base64 encoding some of its Python scripts.

T1033
System Owner/User Discovery

InvisibleFerret has identified the user’s UUID and username through the "pay" module.

T1041
Exfiltration Over C2 Channel

InvisibleFerret has used HTTP communications to the “/Uploads” URI for file exfiltration.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

InvisibleFerret has used FTP to exfiltrate files and directories using the command `ssh_upload` which contains with six subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr` and `sfind` that had varying functions. InvisibleFerret has exfiltrated stolen files and data to the C2 servers over ports 1224, 2245 and 8637.

T1056
Input Capture

InvisibleFerret has collected mouse and keyboard events using “pyWinhook”.

T1056.001
Keylogging

InvisibleFerret has conducted keylogging using the Python project “pyWinHook” and "Pyhook". InvisibleFerret has also captured keylogging thread checks for changes in an active window and key presses.

T1057
Process Discovery

InvisibleFerret has the capability to query installed programs and running processes. InvisibleFerret has also identified running processes using the Python project “psutil”.

T1059.001
PowerShell

InvisibleFerret has utilized a PowerShell script created in the victim’s home directory named “conf.ps1” that is used to modify configuration files for AnyDesk remote services.

T1059.006
Python

InvisibleFerret is written in Python and has used Python scripts for execution.

T1071.001
Web Protocols

InvisibleFerret has used HTTP for C2 communications.

T1074.001
Local Data Staging

InvisibleFerret has staged data in consolidated folders prior to exfiltration.

T1082
System Information Discovery

InvisibleFerret has collected OS type, hostname and system version through the "pay" module. InvisibleFerret has also queried the victim device using Python scripts to obtain the User and Hostname.

T1083
File and Directory Discovery

InvisibleFerret has identified specific directories and files for exfiltration using the `ssh_upload` command which contains subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr`, `sfind`. InvisibleFerret also has the capability to scan and upload files of interest from multiple OS systems through the use of scripts that check file names, file extensions, and avoids certain path names. InvisibleFerret has utilized the `findstr` on Windows or the macOS `find` commands to search for files of interest.

View all 35 procedure examples

Groups that use it1

Campaigns0

None recorded.

References6

  1. ESET Contagious Interview BeaverTail InvisibleFerret February 2025 Open source
    Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.
  2. Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024 Open source
    eSentire Threat Response Unit (TRU). (2024, November 14). Bored BeaverTail & InvisibleFerret Yacht Club – A Lazarus Lure Pt.2. Retrieved October 17, 2025.
  3. PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023 Open source
    Unit 42. (2023, November 21). Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors. Retrieved October 17, 2025.
  4. PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024 Open source
    Unit42. (2024, October 9). Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware. Retrieved October 17, 2025.
  5. Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025 Open source
    Insikt Group. (2025, February 13). Inside the Scam: North Korea’s IT Worker Threat. Retrieved October 17, 2025.
  6. Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 Open source
    Seongsu Park. (2024, November 4). From Pyongyang to Your Payroll: The Rise of North Korean Remote Workers in the West. Retrieved October 17, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.