Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Tricks macOS Users to Execute Command in Terminal to Deliver FlexibleFerret Malware

Cybercriminals are successfully targeting Apple users through a sophisticated social engineering scheme that tricks victims into running harmful commands on their computers.

Cybercriminals are successfully targeting Apple users through a sophisticated social engineering scheme that tricks victims into running harmful commands on their computers.

The threat, called FlexibleFerret, is attributed to North Korean operators and represents a continuing evolution of the Contagious Interview campaign that has been active throughout 2025.

The malware primarily spreads through fake job recruitment websites that promise employment opportunities but ultimately deliver credential-stealing backdoors and system access to attackers.

LinkedIn post highlighting recruitment scams (Source – Jamf) The attack begins innocuously with job seekers visiting realistic-looking hiring assessment websites like evaluza.com and proficiencycert.com.

Victims complete fake job assessments branded with names like “Blockchain Capital Operations Manager Hiring Assessment,” providing personal details and even recording video introductions.

After completing these stages, applicants receive a critical instruction to run a specific Terminal command, which the attackers claim is needed to fix camera or microphone access issues.

Jamf security analysts identified this new variant after discovering in-the-wild detections linked to the script named macpatch.sh.

Jamf security analysts identified this new variant after discovering in-the-wild detections linked to the script named macpatch.sh.
Heather Lyons · Thehackingpost

The researchers found JavaScript files on fraudulent recruitment sites designed to build and execute curl commands that download malicious payloads directly to victims’ computers.

The infection mechanism employs a multi-stage delivery process that remains hidden from users. When the initial curl command executes, it downloads a shell script that determines whether the victim’s Mac uses ARM64 or Intel architecture, then fetches the appropriate stage-two payload.

The script creates working directories in temporary locations, establishes persistence through LaunchAgents that automatically launch the malware at login, and displays a convincing fake Chrome application that mimics a legitimate password prompt.

Left – fake Chrome camera access prompt, Right – Chrome-style password prompt (Source – Jamf) This decoy application captures whatever credentials users enter and sends them to a Dropbox account controlled by the attackers.

The third stage activates when a bundled runs, establishing communication with a command-and-control server.

Advertisement

This sophisticated component supports multiple operations including system information collection, file upload and download capabilities, command execution, Chrome profile theft, and automated credential harvesting.

The backdoor maintains persistence through LaunchAgent entries and includes error-handling mechanisms that reset the malware if temporary failures occur.

Organizations should educate employees to view unsolicited job assessment requests and Terminal-based fix instructions with extreme suspicion.

Any recruitment communication asking users to execute system commands represents a significant red flag and should be reported immediately to security teams.

Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates,  Set CSN as a Preferred Source in  Google .

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories