s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.friendlyferret

📛 Threat Title

Malware family: FriendlyFerret

Category: FriendlyFerret First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.friendlyferret`. Printable name: FriendlyFerret.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.friendlyferret VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.friendlyferret

IOC database

Type
domain
Value
osx.friendlyferret
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.friendlyferret

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.friendlyferret

References (1)

Remediations (10)

  • web:blog.netmanageit.com

    The malware remains undetected by Apple's XProtect tool, highlighting the evolving nature of the threat. OPENCTI LABELS : macos,dropper,github,persistence,developers,dprk,contagious interview,friendlyferret_secd,flexibleferret,frostyferret_ui,chromeupdate,multi_frostyferret_cmdcodes Open in NetmanageIT OpenCTI Public Instance with below link!

  • web:cybercory.com

    The cybersecurity landscape continues to evolve, with nation-state actors increasingly targeting macOS systems. In a recent development, Apple has pushed updates to its on-device malware detection tool, XProtect, to block new variants of the DPRK-attributed "Ferret" malware family . Dubbed "FlexibleFerret," this latest iteration of macOS malware is linked to North Korea's ...

  • web:cyberpress.org

    Disguised Persistence FlexibleFerret represents an evolution of earlier "Ferret" malware components, such as FRIENDLYFERRET_SECD and FROSTYFERRET_UI, which masqueraded as legitimate software or system files. These malware variants gained attention for their ability to exploit social engineering tactics, often targeting job seekers or developers on platforms like GitHub. Victims were ...

  • web:cybersecuritynews.com

    The Ferret family of malware , including variants like FROSTYFERRET_UI and FRIENDLYFERRET_SECD, was first reported in December 2023. These malware components are associated with the "Contagious Interview" campaign, where threat actors trick job seekers into installing malware by masquerading it as necessary software for virtual interviews.

  • web:hivepro.com

    A new wave of macOS malware , attributed to North Korean threat actors, is actively targeting users through the "Contagious Interview" campaign. This attack exploits job seekers and developers, tricking them into installing malware disguised as legitimate applications. Apple recently updated its XProtect malware detection tool to block several known variants, including FRIENDLYFERRET ...

  • web:securitricks.com

    Description This intelligence analysis describes newly discovered variants of the DPRK -attributed macOS Ferret malware family , labeled as ' FlexibleFerret '. The malware is part of the ongoing ' Contagious Interview ' campaign targeting developers and job seekers. The new variants include a dropper package containing multiple components, including a fake Zoom binary and an InstallerAlert ...

  • web:www.csoonline.com

    The macOS Ferret family , variants of malware used by North Korean APTs for cyber espionage, has received a new member as samples of a detection-resistant variant, Flexible-Ferret, appear in the ...

  • web:www.globalsecuritymag.com

    Last week Apple pushed a signature update to its on-device malware tool XProtect to block several variants of what it called the macOS Ferret family : FROSTYFERRET_UI, FRIENDLYFERRET_SECD, and MULTI_FROSTYFERRET_CMDCODES.

  • web:www.nsi-ca.com

    Last week Apple pushed a signature update to its on-device malware tool XProtect to block several variants of what it called the macOS Ferret family : FROSTYFERRET_UI, FRIENDLYFERRET_SECD, and MULTI_FROSTYFERRET_CMDCODES. This DPRK-attributed malware family was first described by researchers in December and further in early January and identified as part of the North Korean Contagious Interview ...

  • web:www.sentinelone.com

    Last week Apple pushed a signature update to its on-device malware tool XProtect to block several variants of what it called the macOS Ferret family : FROSTYFERRET_UI, FRIENDLYFERRET_SECD, and MULTI_FROSTYFERRET_CMDCODES. This DPRK-attributed malware family was first described by researchers in December and further in early January and identified as part of the North Korean Contagious Interview ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.