#FlexibleFerret
Malware/Tool
FlexibleFerret is macOS malware attributed to DPRK-aligned operators and associated with the Contagious Interview campaign. It targets job seekers and developers through staged recruitment tasks, spear-phishing, fake software installers, and instructions to run Terminal commands; reported lures include fake video-conferencing tools and Google Chrome updates. Samples use LaunchAgents for persistence, masquerade as legitimate system processes or applications, and have appeared with a valid Apple Developer ID signature. Reporting links the campaign to worldwide targets in cryptocurrency, finance, and software development and describes credential theft as an objective. GitHub has also been used to distribute malware in this activity.
-
4
Tagged Reports
-
4
Unique Authors
-
296
Active Days