FlexibleFerret malware continues to strike
ID: 42726e7e-785b-5327-a225-73ee4bb27322
STIX ID: report--42726e7e-785b-5327-a225-73ee4bb27322
Feed Name: Jamf Blog
FlexibleFerret is an active multi-stage macOS malware campaign that leverages fake recruitment websites and social engineering to trick victims into running Terminal commands. The attack chain downloads a stage-two shell script (/var/tmp/macpatch.sh) which fetches and unpacks a Go-based backdoor (CDrivers) that maintains persistence via a LaunchAgent, communicates with a hard-coded C2, and exfiltrates credentials (via a decoy MediaPatcher app using Dropbox API); the report provides technical analysis, IoCs (hashes, domains, URLs, IP), and recommendations to treat Terminal-based interview "fix" instructions as high risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
