2024-10-14 Lazarus InvisibleFerret.pdf
ID: d0678456-2e68-469a-a19b-e892762695f4
STIX ID: report--d0678456-2e68-469a-a19b-e892762695f4
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2024-10-14
Last Modified Date: 2024-10-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report provides a detailed analysis of the Lazarus group's 'InvisibleFerret' malware campaign: a Python-based downloader that deploys a backdoor, browser infostealer, and Windows keylogger, using heavy obfuscation and automated pip installs; it documents C2 servers, attack capabilities (keylogging, credential and card theft, remote control, exfiltration via FTP/API), and supplies MD5 hashes and URLs as IOCs for detection and response.
