logo

InvisibleFerret Malware Uses .pyd and .so Files to Evade Script Detection

ID: 59b87ce0-ed6a-5971-a16d-b8f19a511813

STIX ID: report--59b87ce0-ed6a-5971-a16d-b8f19a511813

Feed Name: GBHackers

Threat Score
86/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

Author: Mayura Kathir

...
...

A Trend Micro-derived report describes Void Dokkaebi (aka Famous Chollima) upgrading its InvisibleFerret toolset by compiling Python payloads into Cython-based .pyd/.so modules to evade script-based detection. The campaign uses a JavaScript loader (BeaverTail) to drop and execute modular, obfuscated payloads that provide backdoor access and steal browser credentials, CI/CD secrets, and cryptocurrency wallets—posing a heightened risk to developers and organizations with exposed developer assets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.