Revamped FlexibleFerret Malware Chain Targets macOS Systems

Revamped FlexibleFerret Malware Chain Targets macOS Systems

First seen 26 Nov 2025, 19:33 UTC Infosecurity-MagazineScworld 84% similarity 39.0

Article Content

Browse articles
ThreatCluster

The North Korea-linked FlexibleFerret malware has been updated to enhance its stealth and persistence on macOS systems. The new attack chain includes a second-stage shell script that fetches payloads based on the system architecture and utilizes a Go-based backdoor to maintain long-term access while bypassing user safeguards.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story