Scworld Revamped FlexibleFerret Malware Chain Targets macOS Systems
Article Content
Browse articles
The North Korea-linked FlexibleFerret malware has been updated to enhance its stealth and persistence on macOS systems. The new attack chain includes a second-stage shell script that fetches payloads based on the system architecture and utilizes a Go-based backdoor to maintain long-term access while bypassing user safeguards.
Ask AI about this cluster
Answers cite the sources they use
Updated 197d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track FlexibleFerret and CDrivers in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Fake Recruiter Scams Spread Malware via Git Repositories A recent cybersecurity incident involves fake recruiters sharing malicious Git repositories disguised as coding interview materials. Victims are tricked into downloading these repos, which contain Git hooks that execute scripts upon standard Git commands, leading to the installation of malware. The malware often…
New WeaselBiscuit JavaScript Stealer Discovered in npm Packages Cybersecurity researchers identified a new JavaScript stealer named WeaselBiscuit, which spreads through 13 malicious npm packages. This malware is believed to have functional overlaps with DPRK-associated strains BeaverTail and OtterCookie but is smaller and lacks certain advanced features. It operates by executing a…