New FlexibleFerret Malware Chain Targets macOS With Go Backdoor
ID: 398f6c4a-eee2-57e7-ab04-a7658abd4706
STIX ID: report--398f6c4a-eee2-57e7-ab04-a7658abd4706
Feed Name: Infosecurity Magazine (News)
Threat Score
A macOS malware chain attributed to FlexibleFerret employs staged shell scripts that fetch platform-specific payloads, deploy a Go-based backdoor (CDrivers), establish persistence via a LaunchAgent, and present Chrome-style decoy prompts to harvest credentials which are exfiltrated to Dropbox; the backdoor supports system profiling, file transfer, remote command execution, and automated credential theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
