TF-MAL-osx.flexibleferret
📛 Threat Title
Malware family: FlexibleFerret
Description
ThreatFox malware family `osx.flexibleferret`. Printable name: FlexibleFerret.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.flexibleferret
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.flexibleferret
IOC database
- Type
- domain
- Value
osx.flexibleferret- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.flexibleferret
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.flexibleferret
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bearyangry.com
North Korea‑attributed FlexibleFerret malware is evolving to bypass Apple's XProtect signatures and target macOS users through deceptive job‑interview phishing. The latest dropper, versus.pkg, installs a fake Zoom binary and a malicious installer alert that tricks users into executing a backdoor. It leverages valid Apple Developer certificates, making detection harder for traditional AV ...
-
web:cyberpress.org
In a concerning escalation of macOS-targeted cyberattacks, researchers have unearthed a new variant of the notorious DPRK-attributed malware family , dubbed " FlexibleFerret ." This malware is part of the advanced "Contagious Interview" campaign, which has been linked to North Korean threat actors and was first identified in late 2023. FlexibleFerret reportedly bypasses Apple's native ...
-
web:cybersecsentinel.com
Malware Used: FERRET Malware Family (including variants such as FlexibleFerret , InvisibleFerret, BeaverTail) Threat Score: High (8.5/10) - Due to its sophisticated social engineering techniques, advanced malware capabilities, and targeting of critical sectors
-
web:cybersecuritynews.com
A new variant of malware , known as FlexibleFerret , has been identified targeting macOS users while evading detection by Apple's XProtect tool. This malware is part of a broader campaign attributed to North Korean threat actors, who have been using sophisticated tactics to lure victims into installing malicious software. The Ferret family of malware , including variants like FROSTYFERRET_UI ...
-
web:www.csoonline.com
The macOS Ferret family , variants of malware used by North Korean APTs for cyber espionage, has received a new member as samples of a detection-resistant variant, Flexible-Ferret , appear in the ...
-
web:www.fortinet.com
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.
-
web:www.infosecurity-magazine.com
A new macOS malware chain that uses staged scripts, credential-harvesting decoys and a persistent Go-based backdoor has been observed to bypass user safeguards, disguise its activity and maintain long-term access to compromised systems. According to a new advisory from Jamf Threat Labs, the campaign ...
-
web:www.pcrisk.com
What kind of malware is FlexibleFerret ? FlexibleFerret is a piece of malicious software belonging to a Mac malware family dubbed "Ferret". This group of programs is linked to North Korean threat actors. Ferret programs (including FlexibleFerret ) have been spread through fake job interviews and software repositories. FlexibleFerret malware overview FlexibleFerret arrives onto systems through an ...
-
web:www.planetjon.net
Despite Apple's recent signature updates to its XProtect malware detection tool, this latest variant demonstrates the ability to bypass protections, raising new concerns about macOS cybersecurity. FlexibleFerret belongs to a broader family of malware known as "FERRET," initially uncovered in December 2024.
-
web:www.sentinelone.com
This DPRK-attributed malware family was first described by researchers in December and further in early January and identified as part of the North Korean Contagious Interview campaign, in which threat actors lure targets to install malware through the job interview process.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.