Breaking
February 5, 2025

This devious new macOS malware disguises itself as Chrome, Zoom installers | usagoldmines.com


  • Apple has offered a patch for Ferret family malware
  • The malware is used in associated with the ‘Contagious Interview’ campaign
  • However some malware is still undetectable, so be on your guard

Apple has delivered a new patch on Xprotect, its on-device malware removal tool, intended to block several variants of the macOS ‘Ferret’ family of threats.

As reported by AppleInsider, the new update will counter several issues, including Ferret variants FRIENDLYFERRET_SECD, FROSTYFERRET_UI, and MULTI_FROSTYFERRET_CMDCODES.

These malware variants are reportedly used by North Korean hackers in what has been dubbed the ‘Contagious Interview’ campaign, in which criminals would create fake job openings, primarily targeting software developers or high–profile industries like defense, government departments, or aerospace. The new updates to Xprotect will help block this family of malware from Mac devices, here’s everything we know so far.

The Ferret Family

These fresh Ferret family variants have been observed by researchers to be associated with the ‘Contagious Interview’ campaign. This attack prompts targets to communicate with an interviewer through a link which would show an error message – urging victims to install or update a communication software for virtual meetings.

These ‘updates’ would be disguised as Chrome or Zoom installers, like ChromeUpdate and CameraAccess persistence modules (really FROSTYFERRET_UI). These apps install a malicious persistence agent which runs in the background and steals sensitive data from the victim.

The latest Xprotect update will block most known variants which are disguised as macOS system files – including com.apple.secd (FRIENDLYFERRET). However, not all FlexibleFerret variants can be detected, as the malware landscape evolves so quickly.

The campaign has been observed as far back as 2023, and has been attributed to the well known Lazarus hacking group, which has been observed running several malicious job campaigns to trick jobseekers into downloading malware or trojanized remote access tools.

The data these attackers can access is dependent on the device they infect. Aaron Walton, Threat Intelligence Analyst at Expel points out anyone who falls victim to an attack using their work device, unwittingly puts their organization at risk.

“Though these bad actors typically target people through job offers, it’s fairly common that the individual will run the malware on a corporate device,” he notes. “The attackers often know this and use it as a means to gain information from their target organization.”

Malware protection

At its origin, this is a social engineering campaign, so staying safe from these attacks is much easier if you can spot the signs. Social engineering attacks like phishing are often personalized, sometimes using information obtained from the dark web – obtained in a data breach, for example.

In this instance, the victims handed their information over as part of the ‘job application’ process, so thoroughly vetting any sites and companies you submit job applications to is really important.

Companies can’t stop phishing attacks, and human error will always put organizations at risk, so to mitigate the risks every company, no matter what size, needs a robust cybersecurity strategy. Take a look at our SMB cybersecurity checklist to make sure you’re covered.

“For organizations, it is important to have a strong defense-in-depth strategy—think of it as a multi-layered security fortress, where if one defense fails, another may stop the activity. That is, to defend the environment from many different angles. Employ endpoint detection, monitor networks, and empower employees to report suspicious activities”, Walton comments.

As with most cyberattacks, vigilance is key. New malware threats are rising faster than ever, so being able to spot the signs can help limit the damage. If your device is suddenly much slower than normal, frequently crashes, or randomly reboots those are all signs that your device may be infected.

Another tell-tale sign is persistent pop-ups. These often bogus ads are pretty harmless themselves, but clicking on them might take you to a malicious site, and the ads are often a sign your device is infected. For a more detailed explanation of what to look for, check out our guide here.

For anyone who thinks this may apply to them, check out our list for the best antivirus software, which can be really helpful in locating and removing malware, as well as protecting against repeat infections.

If you do find malware on your device, make sure to remove the infected program immediately. Alongside this, it’s a good idea to disconnect from the internet to prevent the malware from spreading.

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Windows’ new modular game downloads could save your storage drive | usagoldmines.com

Best PC computer deals: Top picks from desktops to all-in-ones | usagoldmines.com

You Can Get a Pixel 8 Pro for $400 Off or a Pixel 8 for $300 Off Kellen | usagoldmines.com

Use the '20/10' Method When You Don't Have the Energy to Clean Lindsey Ellefson | usagoldmines.com

Your Temu and Shein Purchases Are About to Get More Expensive Michelle Ehrhardt | usagoldmines.com

Malware With Screen Reading Code Found in iOS Apps for the First Time Juli Clover | usagoldmines.com

Absurdly powerful PC with 7 liquid-cooled Nvidia RTX 5090 GPUs has just gone on sale — and it is in ...

AMD patches high severity security flaw affecting Zen chips | usagoldmines.com

No, iOS 18.3 doesn't install Starlink on your iPhone – here's what the latest update does, and why y...

Quantum teleportation used to distribute a calculation John Timmer | usagoldmines.com

Hugging Face clones OpenAI’s Deep Research in 24 hours Benj Edwards | usagoldmines.com

7-Zip 0-day was exploited in Russia’s ongoing invasion of Ukraine Dan Goodin | usagoldmines.com

Not Gouda-nough: Google removes AI-generated cheese error from Super Bowl ad Kyle Orland | usagoldmi...

AMD promises “mainstream” 4K gaming with next-gen GPUs as current-gen GPU sales tank Andrew Cunningh...

Best laptops 2025: Premium, budget, gaming, 2-in-1s, and more | usagoldmines.com

Best 4K monitors 2024: HDR, 144Hz, budget, and best overall | usagoldmines.com

Best video doorbells 2025: Reviews and buying advice | usagoldmines.com

This 34-inch Asus ultrawide OLED gaming monitor is just $750 | usagoldmines.com

Best free VPN of 2025: It’s important to choose wisely | usagoldmines.com

Windows will soon be jamming to MIDI 2.0’s music services | usagoldmines.com

The Cheapest Ways to Get Your Protein Right Now Beth Skwarecki | usagoldmines.com

How to Update Your Bathroom to Reduce the Risk of Mold Jeff Somers | usagoldmines.com

Google Launches New Versions of Gemini, Including 'Thinking' Model Juli Clover | usagoldmines.com

HDMI 2.2 vs. DisplayPort 2.1b: The future of display connectors, explained | usagoldmines.com

Which PC components should you upgrade first? | usagoldmines.com

Snag this 1TB Samsung microSD card for $70, its lowest-ever price | usagoldmines.com

Avast One review: Well-priced PC security with excellent protection | usagoldmines.com

This RTX-powered Acer Nitro gaming laptop is $300 off right now | usagoldmines.com

GrubHub got hacked. Go change your password! | usagoldmines.com

AMD says RX 9070 and 9070 XT will arrive ‘in early March’ | usagoldmines.com

Get peace of mind at home with a Ring Battery Doorbell, now 40% off | usagoldmines.com

Stop saving your email login info in your password manager | usagoldmines.com

Patch your Netgear router right now! | usagoldmines.com

eBay’s newest Nvidia GPU scams are even dumber than before | usagoldmines.com

My favorite mechanical gaming keyboard is just $80 right now | usagoldmines.com

Sonos is in trouble. A pricey streaming box won’t help | usagoldmines.com

Tapo D225 Video Doorbell review: High value, low fashion | usagoldmines.com

I Love This App That Lets You Rent Out Your Clothes Lindsey Ellefson | usagoldmines.com

China is quietly pushing ahead with massive 50,000Mbps broadband rollout to leapfrog rest of the wor...

What the weak yen might mean for Switch 2 pricing Kyle Orland | usagoldmines.com

Polestar CEO says the brand’s tech makes the US a “great market for us” Jonathan M. Gitlin | usagold...

Robocallers posing as FCC staff blocked after robocalling real FCC staff Jon Brodkin | usagoldmines....

Which PC components should you upgrade first? | usagoldmines.com

OpenAI Just Introduced More Ways to Use ChatGPT on WhatsApp Jake Peterson | usagoldmines.com

25 of My Favorite Dessert Recipes That Don’t Use (Increasingly Expensive) Eggs Allie Chanthorn Reinm...

An Apple TV Refresh is Coming in 2025 - Here's What You Should Know Juli Clover | usagoldmines.com

The leaked Sonos streaming box could be a huge hit for custom home theaters, if it adds 2 key missin...

Chinese hackers develop effective new hacking technique to go after business networks | usagoldmine...

Chaos and confusion as USPS halts, then resumes parcels from China Ashley Belanger | usagoldmines.co...

Let’s Encrypt is ending expiration notice emails—for some very good reasons Kevin Purdy | usagoldmin...

Stop saving your email login info in your password manager | usagoldmines.com

February Google Play Updates: Here’s What’s New This Month in Android Kellen | usagoldmines.com

Google Updates Gemini 2.0 Models, Released for All Users Tim | usagoldmines.com

Experts warn DeepSeek is 11 times more dangerous than other AI chatbots chiara.castro@futurenet.com ...

Windows 11’s Start menu search gets new, clearer labels, as Microsoft tries to avoid EU regulation t...

Nikon's first 35mm f/1.2 looks like my dream prime lens – apart from the price tag | usagoldmines.c...

Amazon just sent invites for a February 26 event, and we might finally see the debut of the next-gen...

Less than half of ransomware incidents end in payment - but you should still be on your guard | usa...

Samsung Galaxy Z Flip 7: latest news, rumors, and everything we’ve heard so far | usagoldmines.com

OpenAI is getting a makeover - new visual rebrand for ChatGPT maker even includes its own custom fon...

Sony was making a space shooter for its unreleased Nintendo PlayStation console, according to Shuhei...

Don't worry about the Nintendo Switch 2 price, Nintendo says it will follow the 'affordable prices c...

Which PC components should you upgrade first? | usagoldmines.com

You Should Enable the Shortcut Feature in the Android Google Widget Khamosh Pathak | usagoldmines.co...

You Can Now Unsend Outlook Emails on Mac Pranay Parab | usagoldmines.com

Apple's Do-It-Yourself Repair Store Now Offering Parts for M4 Macs Joe Rossignol | usagoldmines.com

Bring it on Nvidia - AMD confirms new Radeon RX 9000 series GPUs will launch in early March, rivalin...

Getting to grips with Adversary-in-the-Middle threats | usagoldmines.com

A cracked malicious version of a Go package lay undetected online for years | usagoldmines.com

Jurassic World Rebirth roars into theaters this July Jennifer Ouellette | usagoldmines.com

These Beats Studio Buds Are at Their Lowest Price Ever Right Now Pradershika Sharma | usagoldmines.c...

Google’s Latest Android Update Patches 47 Security Flaws David Nield | usagoldmines.com

Apple's M4 iMac (8-Core/256GB) Drops to $1,149.99 on Amazon, More Models at Up to $175 Off Mitchel B...

Australian and Indian governments block DeepSeek from worker devices | usagoldmines.com

A Buffy the Vampire Slayer reboot could be headed to Hulu, and I’m both excited and nervous for the ...

Monster Hunter Wilds' PS5 Pro enhancements have been detailed and will offer three different graphic...

First trailer for Jurassic World Rebirth teases strong ties to 1993's Jurassic Park, and I can't hel...

The Switch 2 Nintendo Direct now has official times for its April 2 broadcast | usagoldmines.com

LinkedIn is releasing even more video tools as it looks to take on TikTok, Instagram | usagoldmines...

Netgear urges users to patch major router security issues now | usagoldmines.com

Sovereign Cloud: redefining the future of secure digital innovation | usagoldmines.com

Tackling the threat of deepfakes in the workplace | usagoldmines.com

$58 billion Honda-Nissan merger is in deep trouble Harry Dempsey, David Keohane, and Kana Inagaki, F...

After a wrenching decision by NASA, private lunar lander finds a new customer Eric Berger | usagoldm...

Teslas turn toxic as sales crash in Europe and the UK Jonathan M. Gitlin | usagoldmines.com

Best USB-C cables 2025: Get quality charging and data transfers | usagoldmines.com

Best antivirus software 2025: Keep your PC safe from malware, spyware, and more | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

Why You Should Try Potassium Salt (and How It Tastes) Beth Skwarecki | usagoldmines.com

Where to Find All Those Deleted Government Websites Emily Long | usagoldmines.com

macOS Sequoia 15.3 Fixes SuperDuper Bootable Backups Bug Tim Hardwick | usagoldmines.com

Ferrari reveals 2025 launch date for its first fully electric car –here's everything we know | usag...

Oppo is launching the world's thinnest foldable in two weeks – and the OnePlus Open 2 should follow ...

Panasonic may leave the TV business, and that would be a crying shame | usagoldmines.com

Google Gemini update makes asking the AI for assistance feel more like phoning a friend hamish.hecto...

Israeli spyware company confirms US government and friends are customers benedict.collins@futurenet....

US Postal Service blocks all small parcels from China, crippling ecommerce firms like Temu and Shein...

85% of UK employers admit to spying on their employees – and workers aren't happy chiara.castro@futu...

Windows 10 dies in 2025: Why you shouldn’t brush off the risks | usagoldmines.com

M5 Apple Silicon Chip Reportedly Enters Mass Production Tim Hardwick | usagoldmines.com

Leave a Reply