11/29/2025
Researchers have discovered a new attack targeting Mac users. It lures them to a fake job website, then tricks them into downloading malware via a bogus software update.
The attackers pose as recruiters and contact people via LinkedIn, encouraging them to apply for a role. As part of the application process, victims are required to record a video introduction and upload it to a special website.
Victims are then given a curl command to run in their Terminal. That command downloads a script which ultimately installs a backdoor called "FlexibleFerret" onto their system. A a window then appears that looks like Chrome, telling the user that Chrome needs camera access. Next, a window prompts for the user’s password, which, once entered, is sent to the attackers via Dropbox.
FlexibleFerret’s core payload is a Go-based backdoor. It enables attackers to:
Collect detailed information about the victim’s device and environment,
Upload and download files,
Execute shell commands (providing full system control),
Extract Chrome browser profile data,
Automate additional credential and data theft,
The infected Mac is now a remote-controlled botnet with direct access for cybercriminals.
How to stay safe:
Keep your systems updates and use Zero Trust solutions, like ThreatLocker.
Want to learn more? Give us a call!