← Back to Feed
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware
May 22, 2026 · Trend Micro · Severity: HIGH
Void Dokkaebi, a North Korea-aligned intrusion set, has updated its information-stealing malware, InvisibleFerret, shifting its delivery format to evade script-based detections.
Key Takeaways
- Void Dokkaebi, a North Korea-aligned intrusion set, updated its InvisibleFerret infostealer malware.
- The malware shifted delivery format to Cython compilation to evade script-based detections.
- The Cython-compiled InvisibleFerret evades traditional script-based malware detection.