logo

2024-10-14 Lazarus InvisibleFerret.pdf

ID: d0678456-2e68-469a-a19b-e892762695f4

STIX ID: report--d0678456-2e68-469a-a19b-e892762695f4

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2024-10-14

Last Modified Date: 2024-10-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report provides a detailed analysis of the Lazarus group's 'InvisibleFerret' malware campaign: a Python-based downloader that deploys a backdoor, browser infostealer, and Windows keylogger, using heavy obfuscation and automated pip installs; it documents C2 servers, attack capabilities (keylogging, credential and card theft, remote control, exfiltration via FTP/API), and supplies MD5 hashes and URLs as IOCs for detection and response.