logo

Ferret Malware Added to 'Contagious Interview' Campaign

ID: ee7452e1-24bc-590e-b6f6-ef99dd009984

STIX ID: report--ee7452e1-24bc-590e-b6f6-ef99dd009984

Feed Name: Dark Reading

Threat Score
76/100

Date Published: 2025-02-04

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

Apple distributed XProtect signature updates to block variants of the macOS "Ferret" malware family tied to a DPRK campaign called “Contagious Interview,” in which targets are tricked into installing malicious software via fake job-interview links. The campaign drops JavaScript (BeaverTail) and a Python backdoor (InvisibleFerret) that harvests browser and crypto wallet data; researchers have observed evolving variants (including FlexibleFerret) that have at times evaded detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.