logo

InvisibleFerret Malware Now Ships as .pyd and .so Files to Evade Script Detection

ID: 534a7548-5262-53de-8483-fed2cfee389e

STIX ID: report--534a7548-5262-53de-8483-fed2cfee389e

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-05-25

Date Updated: 2026-05-26

Author: Tushar Subhra Dutta

...
...

InvisibleFerret, an info-stealer tied to the North Korea-linked Void Dokkaebi (Famous Chollima), has been reworked from Python scripts into Cython-compiled native modules (.pyd on Windows, .so on macOS) to evade script-based detection; the campaign uses social engineering against developers to deliver multi-stage infections, and an expanded BeaverTail loader now provides additional credential- and wallet-stealing capabilities and trojanized browser extensions, with multiple IoCs and recommended detection changes provided by analysts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.