Ferret Malware Added to 'Contagious Interview' Campaign
ID: ee7452e1-24bc-590e-b6f6-ef99dd009984
STIX ID: report--ee7452e1-24bc-590e-b6f6-ef99dd009984
Feed Name: Dark Reading
Date Published: 2025-02-04
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
Apple distributed XProtect signature updates to block variants of the macOS "Ferret" malware family tied to a DPRK campaign called “Contagious Interview,” in which targets are tricked into installing malicious software via fake job-interview links. The campaign drops JavaScript (BeaverTail) and a Python backdoor (InvisibleFerret) that harvests browser and crypto wallet data; researchers have observed evolving variants (including FlexibleFerret) that have at times evaded detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
