TF-MAL-osx.friendlyferret
📛 Threat Title
Malware family: FriendlyFerret
Description
ThreatFox malware family `osx.friendlyferret`. Printable name: FriendlyFerret.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.friendlyferret
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.friendlyferret
IOC database
- Type
- domain
- Value
osx.friendlyferret- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.friendlyferret
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.friendlyferret
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.netmanageit.com
The malware remains undetected by Apple's XProtect tool, highlighting the evolving nature of the threat. OPENCTI LABELS : macos,dropper,github,persistence,developers,dprk,contagious interview,friendlyferret_secd,flexibleferret,frostyferret_ui,chromeupdate,multi_frostyferret_cmdcodes Open in NetmanageIT OpenCTI Public Instance with below link!
-
web:cybercory.com
The cybersecurity landscape continues to evolve, with nation-state actors increasingly targeting macOS systems. In a recent development, Apple has pushed updates to its on-device malware detection tool, XProtect, to block new variants of the DPRK-attributed "Ferret" malware family . Dubbed "FlexibleFerret," this latest iteration of macOS malware is linked to North Korea's ...
-
web:cyberpress.org
Disguised Persistence FlexibleFerret represents an evolution of earlier "Ferret" malware components, such as FRIENDLYFERRET_SECD and FROSTYFERRET_UI, which masqueraded as legitimate software or system files. These malware variants gained attention for their ability to exploit social engineering tactics, often targeting job seekers or developers on platforms like GitHub. Victims were ...
-
web:cybersecuritynews.com
The Ferret family of malware , including variants like FROSTYFERRET_UI and FRIENDLYFERRET_SECD, was first reported in December 2023. These malware components are associated with the "Contagious Interview" campaign, where threat actors trick job seekers into installing malware by masquerading it as necessary software for virtual interviews.
-
web:hivepro.com
A new wave of macOS malware , attributed to North Korean threat actors, is actively targeting users through the "Contagious Interview" campaign. This attack exploits job seekers and developers, tricking them into installing malware disguised as legitimate applications. Apple recently updated its XProtect malware detection tool to block several known variants, including FRIENDLYFERRET ...
-
web:securitricks.com
Description This intelligence analysis describes newly discovered variants of the DPRK -attributed macOS Ferret malware family , labeled as ' FlexibleFerret '. The malware is part of the ongoing ' Contagious Interview ' campaign targeting developers and job seekers. The new variants include a dropper package containing multiple components, including a fake Zoom binary and an InstallerAlert ...
-
web:www.csoonline.com
The macOS Ferret family , variants of malware used by North Korean APTs for cyber espionage, has received a new member as samples of a detection-resistant variant, Flexible-Ferret, appear in the ...
-
web:www.globalsecuritymag.com
Last week Apple pushed a signature update to its on-device malware tool XProtect to block several variants of what it called the macOS Ferret family : FROSTYFERRET_UI, FRIENDLYFERRET_SECD, and MULTI_FROSTYFERRET_CMDCODES.
-
web:www.nsi-ca.com
Last week Apple pushed a signature update to its on-device malware tool XProtect to block several variants of what it called the macOS Ferret family : FROSTYFERRET_UI, FRIENDLYFERRET_SECD, and MULTI_FROSTYFERRET_CMDCODES. This DPRK-attributed malware family was first described by researchers in December and further in early January and identified as part of the North Korean Contagious Interview ...
-
web:www.sentinelone.com
Last week Apple pushed a signature update to its on-device malware tool XProtect to block several variants of what it called the macOS Ferret family : FROSTYFERRET_UI, FRIENDLYFERRET_SECD, and MULTI_FROSTYFERRET_CMDCODES. This DPRK-attributed malware family was first described by researchers in December and further in early January and identified as part of the North Korean Contagious Interview ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.