s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.flexibleferret

📛 Threat Title

Malware family: FlexibleFerret

Category: FlexibleFerret First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.flexibleferret`. Printable name: FlexibleFerret.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.flexibleferret VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.flexibleferret

IOC database

Type
domain
Value
osx.flexibleferret
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.flexibleferret

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.flexibleferret

References (1)

Remediations (10)

  • web:bearyangry.com

    North Korea‑attributed FlexibleFerret malware is evolving to bypass Apple's XProtect signatures and target macOS users through deceptive job‑interview phishing. The latest dropper, versus.pkg, installs a fake Zoom binary and a malicious installer alert that tricks users into executing a backdoor. It leverages valid Apple Developer certificates, making detection harder for traditional AV ...

  • web:cyberpress.org

    In a concerning escalation of macOS-targeted cyberattacks, researchers have unearthed a new variant of the notorious DPRK-attributed malware family , dubbed " FlexibleFerret ." This malware is part of the advanced "Contagious Interview" campaign, which has been linked to North Korean threat actors and was first identified in late 2023. FlexibleFerret reportedly bypasses Apple's native ...

  • web:cybersecsentinel.com

    Malware Used: FERRET Malware Family (including variants such as FlexibleFerret , InvisibleFerret, BeaverTail) Threat Score: High (8.5/10) - Due to its sophisticated social engineering techniques, advanced malware capabilities, and targeting of critical sectors

  • web:cybersecuritynews.com

    A new variant of malware , known as FlexibleFerret , has been identified targeting macOS users while evading detection by Apple's XProtect tool. This malware is part of a broader campaign attributed to North Korean threat actors, who have been using sophisticated tactics to lure victims into installing malicious software. The Ferret family of malware , including variants like FROSTYFERRET_UI ...

  • web:www.csoonline.com

    The macOS Ferret family , variants of malware used by North Korean APTs for cyber espionage, has received a new member as samples of a detection-resistant variant, Flexible-Ferret , appear in the ...

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

  • web:www.infosecurity-magazine.com

    A new macOS malware chain that uses staged scripts, credential-harvesting decoys and a persistent Go-based backdoor has been observed to bypass user safeguards, disguise its activity and maintain long-term access to compromised systems. According to a new advisory from Jamf Threat Labs, the campaign ...

  • web:www.pcrisk.com

    What kind of malware is FlexibleFerret ? FlexibleFerret is a piece of malicious software belonging to a Mac malware family dubbed "Ferret". This group of programs is linked to North Korean threat actors. Ferret programs (including FlexibleFerret ) have been spread through fake job interviews and software repositories. FlexibleFerret malware overview FlexibleFerret arrives onto systems through an ...

  • web:www.planetjon.net

    Despite Apple's recent signature updates to its XProtect malware detection tool, this latest variant demonstrates the ability to bypass protections, raising new concerns about macOS cybersecurity. FlexibleFerret belongs to a broader family of malware known as "FERRET," initially uncovered in December 2024.

  • web:www.sentinelone.com

    This DPRK-attributed malware family was first described by researchers in December and further in early January and identified as part of the North Korean Contagious Interview campaign, in which threat actors lure targets to install malware through the job interview process.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.