← Back to Feed
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware
May 22, 2026 · Trend Micro · Severity: HIGH
Void Dokkaebi, a North Korea-aligned intrusion set, has updated its information-stealing malware, InvisibleFerret, shifting its delivery format to evade script-based detections.
Key Takeaways
- Void Dokkaebi, a North Korea-aligned intrusion set, updated its information-stealing malware InvisibleFerret by shifting its delivery format.
- The group now distributes InvisibleFerret as Cython-compiled payloads to evade script-based detections on targeted systems.
- Security teams should update detection signatures for InvisibleFerret to handle compiled variants and monitor for North Korean intrusion set activity.