FlexibleFerret malware continues to strike
ID: f8f0cf00-0fba-5633-b7ad-9a6e03e03961
STIX ID: report--f8f0cf00-0fba-5633-b7ad-9a6e03e03961
Feed Name: Jamf Blog
Threat Score
Jamf Threat Labs details an active FlexibleFerret macOS campaign that uses fake recruitment assessments and Terminal-based social engineering to install a multi-stage loader (JavaScript stagers → macpatch.sh → drivfixer.sh → Go backdoor). The malware establishes persistence via a LaunchAgent, exfiltrates captured credentials to Dropbox, contacts a hard-coded C2 (95.169.180.140:8080), and the report provides file hashes, domains, URLs, and file paths as IoCs for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
