logo

Fake LinkedIn jobs trick Mac users into downloading Flexible Ferret malware

ID: b18d4744-5bcb-59d5-be68-e787e7bfe1c4

STIX ID: report--b18d4744-5bcb-59d5-be68-e787e7bfe1c4

Feed Name: Malwarebytes Blog

Threat Score
80/100

Date Published: 2025-11-26

Date Updated: 2026-04-28

...
...

Researchers identified the 'Contagious Interview' social-engineering campaign that lures job applicants to a fake recruitment site, prompts them to execute a malicious update (disguised as FFmpeg) via a curl command, and installs FlexibleFerret — a Go-based macOS backdoor that captures passwords, persists via LaunchAgent, exfiltrates browser/profile data and files, and enables remote command execution; attribution in the report points to DPRK actors and Windows targets face a related stealer (InvisibleFerret).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.