#FrostyFerret
Malware/Tool
FrostyFerret is a macOS member of the DPRK-attributed Ferret malware family used in the Contagious Interview and later ClickFake Interview activity. Operators direct targets from social-media job approaches to fake interview sites, where a camera error prompts installation of a supposed software update. On macOS, a Bash script downloads and extracts malicious components, then runs FrostyFerret to steal the system password before launching the GolangGhost backdoor. A BlockNovas interview delivered FrostyFerret, and related infrastructure hosted BeaverTail malware; reporting also notes that BeaverTail and FrostyFerret shared a command-and-control server. The activity particularly targeted centralized-finance personnel.
-
3
Tagged Reports
-
3
Unique Authors
-
80
Active Days