Skip to content
Revamped FlexibleFerret Malware Chain Targets macOS Systems

Revamped FlexibleFerret Malware Chain Targets macOS Systems

First seen 26 Nov 2025, 19:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

The North Korea-linked FlexibleFerret malware has been updated to enhance its stealth and persistence on macOS systems. The new attack chain includes a second-stage shell script that fetches payloads based on the system architecture and utilizes a Go-based backdoor to maintain long-term access while bypassing user safeguards.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 197d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track FlexibleFerret and CDrivers in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed