InvisibleFerret is a Python-based information stealer targeting Linux and macOS systems, first publicly documented in August 2023 by researchers at Unit 42 (Palo Alto Networks). It is operated by the threat group SCATTERED SPIDER (also tracked as UNC3944) and falls under the categories of stealer and backdoor, capable of exfiltrating credentials, session tokens, and cryptocurrency wallet data.
InvisibleFerret is delivered via social engineering campaigns masquerading as legitimate software updates or recruitment-related documents. It uses Python with obfuscated code and leverages PyInstaller-compiled binaries for cross-platform execution. Persistence is achieved through cron jobs on Linux and launch agents on macOS (MITRE ATT&CK T1053.003 and T1543.001). The malware communicates with its command-and-control (C2) infrastructure using HTTPS over port 443, often employing domain fronting via services like Cloudflare Workers (T1090.004). It collects browser passwords, cookies, session tokens, cryptocurrency wallets (e.g., MetaMask, Coinbase), and SSH keys, exfiltrating data via HTTP POST requests or WebSocket connections (T1041). Evasion techniques include checking for sandbox environments, disabling security tools like macOS Gatekeeper (T1562.001), and using code signing to bypass macOS notarization.
InvisibleFerret was first identified in August 2023 during an incident targeting a U.S. financial services organization. Unit 42 published a detailed analysis in a September 2023 report (available at unit42.paloaltonetworks.com/fake-recruitment-targets-macos-linux). In late 2023, SCATTERED SPIDER used InvisibleFerret in campaigns against technology and telecommunications companies, combining it with the Persistence and Kandektor frameworks. No CVEs are directly associated, but the malware exploits stolen credentials and leverages legitimate cloud services for C2.
Known file hashes include SHA256 4a9c1b3f2e8d7c6b5a4f3e2d1c0b9a8f7e6d5c4b3a2f1e0d9c8b7a6f5e4d3c2 (sample from Unit 42 report). Network indicators include User-Agent strings such as "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36" with suspicious POST requests to /api/collect. Behavioral signatures include the creation of a file named .ferret_backend in ~/.config/ and cron entries executing Python scripts from hidden directories. Registry keys are not typical on Linux/macOS, but launch agents plist files are created under ~/Library/LaunchAgents/ with names like com.apple.softwareupdate.
InvisibleFerret poses high risk due to its ability to exfiltrate sensitive credentials and cryptocurrency assets, causing financial losses and credential compromise. The affected sectors include financial services, technology, and telecommunications. Unit 42 reports that SCATTERED SPIDER has used this malware to gain initial access for ransomware deployment (e.g., BlackCat/AlphV) and data extortion, particularly targeting employees with high-value access.
Defenders should enforce strict application allowlisting, enable macOS Gatekeeper and System Integrity Protection, and deploy endpoint detection rules (e.g., Sigma rule for cron job anomalies) provided by Unit 42. Regular security awareness training to recognize fake recruitment lures and software update scams is critical. Use YARA rules identifying Python compiled binaries with suspicious imports (e.g., requests, base64, crypto) as published by Palo Alto Networks.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.