INTEL_REPORT
Trend Micro Research · published 5/22/2026, 12:00:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware Void Dokkaebi, a North Korea-aligned intrusion set, has updated its information-stealing malware, InvisibleFerret, shifting its delivery format to evade script-based detections. Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate and…
https://www.trendmicro.com/en_us/research/26/e/analyzing-void-dokkaebi-invisibleferret-malware.html
sha256:38ee007683ab54234a7b7cc5c56f6a260e3fc11cd9a6576c326f46e9b38efa6c
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| mod.so |
| Open → |
| domain | mod.pyc | Open → |
| domain | mod.lambda | Open → |
| domain | temp.macosx | Open → |
| domain | pad.pyd | Open → |
| domain | pad.so | Open → |
| domain | brw.pyd | Open → |
| domain | brw.so | Open → |
| domain | mc.so | Open → |
| domain | any.py | Open → |
| domain | vscode.mod | Open → |
| url | http://ip-api.com/json | Open → |
| url | https://portal.xdr.trendmicro.com/index.html | Open → |