As cited
Copy frozen at (site build).
threat intel
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware
Void Dokkaebi, a North Korea-aligned intrusion set, has modified its InvisibleFerret information-stealing malware to use Cython compilation, changing its delivery format to evade script-based detection methods.
Why it matters: Organizations targeted by North Korean threat actors need to update detection logic to identify Cython-compiled variants of InvisibleFerret, as the new obfuscation technique reduces visibility into malware behavior.
- Source published
- First seen by Cybersecurity Tracker