Hackers Tricks macOS Users to Execute Command in Terminal to Deliver FlexibleFerret Malware
ID: 8f753e0e-5c14-57e8-9cd9-e289bf53756c
STIX ID: report--8f753e0e-5c14-57e8-9cd9-e289bf53756c
Feed Name: cybersecurityNews.com
The report details FlexibleFerret, an ongoing 2025 campaign attributed to North Korean operators that lures macOS job seekers to realistic fake recruitment sites which instruct victims to run Terminal commands; these commands fetch a multi-stage payload (macpatch.sh) that installs persistence via LaunchAgents, presents fake Chrome prompts to harvest credentials (exfiltrated to Dropbox), and deploys a Golang backdoor with C2 functionality for data collection, file transfer, command execution, and profile theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
