logo

FlexibleFerret malware continues to strike

ID: 42726e7e-785b-5327-a225-73ee4bb27322

STIX ID: report--42726e7e-785b-5327-a225-73ee4bb27322

Feed Name: Jamf Blog

Threat Score
82/100

Date Published: 2025-11-25

Date Updated: 2026-07-16

...
...

FlexibleFerret is an active multi-stage macOS malware campaign that leverages fake recruitment websites and social engineering to trick victims into running Terminal commands. The attack chain downloads a stage-two shell script (/var/tmp/macpatch.sh) which fetches and unpacks a Go-based backdoor (CDrivers) that maintains persistence via a LaunchAgent, communicates with a hard-coded C2, and exfiltrates credentials (via a decoy MediaPatcher app using Dropbox API); the report provides technical analysis, IoCs (hashes, domains, URLs, IP), and recommendations to treat Terminal-based interview "fix" instructions as high risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.