Fake LinkedIn jobs trick Mac users into downloading Flexible Ferret malware
ID: b18d4744-5bcb-59d5-be68-e787e7bfe1c4
STIX ID: report--b18d4744-5bcb-59d5-be68-e787e7bfe1c4
Feed Name: Malwarebytes Blog
Researchers identified the 'Contagious Interview' social-engineering campaign that lures job applicants to a fake recruitment site, prompts them to execute a malicious update (disguised as FFmpeg) via a curl command, and installs FlexibleFerret — a Go-based macOS backdoor that captures passwords, persists via LaunchAgent, exfiltrates browser/profile data and files, and enables remote command execution; attribution in the report points to DPRK actors and Windows targets face a related stealer (InvisibleFerret).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
