logo

Hackers Tricks macOS Users to Execute Command in Terminal to Deliver FlexibleFerret Malware

ID: 8f753e0e-5c14-57e8-9cd9-e289bf53756c

STIX ID: report--8f753e0e-5c14-57e8-9cd9-e289bf53756c

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-11-27

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

The report details FlexibleFerret, an ongoing 2025 campaign attributed to North Korean operators that lures macOS job seekers to realistic fake recruitment sites which instruct victims to run Terminal commands; these commands fetch a multi-stage payload (macpatch.sh) that installs persistence via LaunchAgents, presents fake Chrome prompts to harvest credentials (exfiltrated to Dropbox), and deploys a Golang backdoor with C2 functionality for data collection, file transfer, command execution, and profile theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.