← Back to Feed

Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware

May 22, 2026 · Trend Micro · Severity: HIGH

Void Dokkaebi, a North Korea-aligned intrusion set, has updated its information-stealing malware, InvisibleFerret, shifting its delivery format to evade script-based detections.

Key Takeaways

  • Void Dokkaebi, a North Korea-aligned intrusion set, updated its InvisibleFerret infostealer malware.
  • The malware shifted delivery format to Cython compilation to evade script-based detections.
  • The Cython-compiled InvisibleFerret evades traditional script-based malware detection.
☕ Buy a Coffee