FERRET
Ferret is a malware family observed from late 2024 and active in campaigns through 2025, primarily targeting macOS users. It has been linked to the North Korean "Contagious Interview" campaign, in which operators use fake job interview or recruitment lures to target software developers, IT professionals, and especially blockchain and cryptocurrency personnel. Researchers reported that Ferret family loaders were distributed through fraudulent online job interview invitations, and past versions delivered both a backdoor and a crypto stealer. Vendors tracking the campaign described the operators as continually evolving their tooling alongside other malware such as BeaverTail.
The Ferret family has also been associated with macOS-focused theft activity. A known strain, FrigidStealer, was first spotted in February 2025 and is described as part of the Ferret malware family. FrigidStealer was delivered via fake browser update prompts, including DMG files disguised as Safari updates, and impacted users across North America, Europe, and Asia. It has been linked to activity clusters TA2726 and TA2727 and to infections in public-facing industries, particularly retail and hospitality. Reported capabilities include theft of browser credentials, system files, cryptocurrency wallet data, and Apple Notes. It exfiltrates data via DNS queries routed through macOS mDNSResponder, installs a malicious app with bundle ID com.wails.ddaolimaki-daunito, uses AppleScript and unauthorized Apple Events, registers as a foreground application via launchservicesd, deletes traces after execution, and terminates itself after exfiltration to reduce detection.
Across reporting, Ferret is consistently characterized as a macOS threat family used in social-engineering-driven intrusion chains and credential or data theft operations, with some reporting noting possible data exfiltration or credential theft against organizations.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Collection of macOS malware strains delivered in the 'Contagious Interview' fake job interview process via social engineering and fake software installs/updates.
A named malware family associated with the North Korea-attributed Contagious Interview campaign; described in the context of data theft/infostealer activity targeting developers.
Ferret is a macOS infostealer family targeting enterprises and high-value individuals, particularly for crypto theft.
CTI Roundup: Ferret Malware, macOS Stealers, and MS Power BI | Tanium
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.