#FrostyFerret

Malware/Tool

2025-02-03 • macOS FlexibleFerret | Further Variants of DPRK Malware Family Unearthed

FrostyFerret is a macOS member of the DPRK-attributed Ferret malware family used in the Contagious Interview and later ClickFake Interview activity. Operators direct targets from social-media job approaches to fake interview sites, where a camera error prompts installation of a supposed software update. On macOS, a Bash script downloads and extracts malicious components, then runs FrostyFerret to steal the system password before launching the GolangGhost backdoor. A BlockNovas interview delivered FrostyFerret, and related infrastructure hosted BeaverTail malware; reporting also notes that BeaverTail and FrostyFerret shared a command-and-control server. The activity particularly targeted centralized-finance personnel.

Tagged Reports

« Back