Friday, September 11, 2026

FlexibleFerret Malware Attacking macOS Users, Evading XProtect Detections

A new macOS malware variant, dubbed “FlexibleFerret,” has been identified targeting developers and job seekers as part of an ongoing North Korean phishing campaign.

Despite Apple’s recent signature updates to its XProtect malware detection tool, this latest variant demonstrates the ability to bypass protections, raising new concerns about macOS cybersecurity.

FlexibleFerret belongs to a broader family of malware known as “FERRET,” initially uncovered in December 2024.

This malware family was attributed to the “Contagious Interview” campaign, where victims were lured through fake job interviews to install malicious software disguised as legitimate applications like virtual meeting tools or browser updates.

Technical Breakdown of FlexibleFerret

Recent investigations by SentinelLabs revealed that the FlexibleFerret variant leverages sophisticated techniques to evade detection.

Delivered via a malicious installer package, titled “versus.pkg,” the dropper includes deceptive components such as InstallerAlert.app and a fake Zoom binary.

FlexibleFerret Malware
File contents of the FlexibleFerret dropper, versus.pkg

The package installs additional scripts and binaries in concealed locations on infected devices, including /var/tmp/ and /private/tmp/, where it achieves persistence and executes its payload.

One of the standout features of the malware is its use of legitimate-looking Apple Developer signatures for credibility.

Although the developer signature linked to FlexibleFerret has since been revoked, threat actors exploited it to bypass macOS Gatekeeper protections during distribution.

The malware mimics system behaviors to avoid arousing suspicion. For instance, one of its executables, InstallerAlert, throws a fake macOS error message, “This file is damaged and cannot be opened,” giving users the impression that the application failed to execute.

In the background, however, the malware establishes persistence mechanisms, such as planting a malicious LaunchAgent file disguised as a legitimate Zoom service, targeting /private/var/tmp/logd for its payload operations.

A Broader Threat Spectrum

The “Contagious Interview” campaign and the FERRET malware family, including FlexibleFerret, reflect a well-coordinated effort by North Korean advanced persistent threat (APT) groups.

These groups target not only job seekers but also developers using repositories like GitHub.

FlexibleFerret Malware
A threat actor tries to trick Github users into downloading FERRET malware

SentinelLabs observed attackers posting fake issues and comments to lure developers into downloading infected files, including components of the FERRET malware.

FlexibleFerret also employs common tactics seen in other North Korea-linked campaigns, such as the use of Dropbox APIs for exfiltration and IP resolution services like api.ipify.org to monitor infected devices.

While Apple has added some FERRET components to XProtect’s blocklist, the FlexibleFerret variant remains undetected by the latest version of the tool.

The emergence of FlexibleFerret underscores the need for heightened vigilance among macOS users, particularly developers.

As attackers expand their malware delivery methods and develop variants capable of evading traditional protections, security best practices including using endpoint protection, avoiding untrusted downloads, and monitoring for indicators of compromise are critical.

Organizations and individuals are encouraged to stay updated with the latest threat intelligence and to employ robust security solutions capable of detecting advanced malware families like FERRET.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News