logo

DPRK's FlexibleFerret Tightens macOS Grip

ID: 777c1b99-841c-504f-abc2-1ea8b83cfab3

STIX ID: report--777c1b99-841c-504f-abc2-1ea8b83cfab3

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2025-11-25

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

FlexibleFerret, a DPRK-linked macOS credential-theft campaign, leverages convincing fake recruitment sites that coax targets into pasting Terminal commands to install an architecture-aware shell loader and a Go-based backdoor; attackers also use signed decoy apps (MediaPatcher.app), improved persistence and C2 capabilities to harvest and exfiltrate credentials, browser data and keychain items, and Jamf reports the campaign is actively evolving.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.