Ferret Frenzy: North Korean Hackers Unleash Mac Malware in Bizarre Job Interview Scam
North Korean threat actors are using LinkedIn to pose as recruiters, luring targets into job interviews that deliver Apple macOS malware strains dubbed FERRET. This sneaky campaign tricks users into downloading malicious software, aiming to steal data and drain MetaMask Wallets, proving once again that not all job offers are golden opportunities.

Hot Take:
North Korean hackers have taken job interviews to a whole new level of terrifying. These cyber masterminds are turning what should be a simple “Tell me about yourself” into a “Tell me where your crypto wallet is.” Who knew LinkedIn recruiters could be so sinister?
Key Points:
- North Korean threat actors are delivering Apple macOS malware through fake job interviews.
- Malware strains, dubbed FERRET, include components like BeaverTail and InvisibleFerret.
- The attack uses fake npm packages and videoconferencing software to drop malware.
- Malware targets sensitive data from web browsers and crypto wallets.
- Hackers use fake LinkedIn recruiters to lure victims into executing malicious commands.
Already a member? Log in here