← Back to Feed

Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware

May 22, 2026 · Trend Micro · Severity: HIGH

Void Dokkaebi, a North Korea-aligned intrusion set, has updated its information-stealing malware, InvisibleFerret, shifting its delivery format to evade script-based detections.

Key Takeaways

  • Void Dokkaebi, a North Korea-aligned intrusion set, updated its information-stealing malware InvisibleFerret by shifting its delivery format.
  • The group now distributes InvisibleFerret as Cython-compiled payloads to evade script-based detections on targeted systems.
  • Security teams should update detection signatures for InvisibleFerret to handle compiled variants and monitor for North Korean intrusion set activity.
☕ Buy a Coffee