logo

New FlexibleFerret Malware Chain Targets macOS With Go Backdoor

ID: 398f6c4a-eee2-57e7-ab04-a7658abd4706

STIX ID: report--398f6c4a-eee2-57e7-ab04-a7658abd4706

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2025-11-25

Date Updated: 2026-04-22

...
...

A macOS malware chain attributed to FlexibleFerret employs staged shell scripts that fetch platform-specific payloads, deploy a Go-based backdoor (CDrivers), establish persistence via a LaunchAgent, and present Chrome-style decoy prompts to harvest credentials which are exfiltrated to Dropbox; the backdoor supports system profiling, file transfer, remote command execution, and automated credential theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.