logo

FlexibleFerret malware continues to strike

ID: f8f0cf00-0fba-5633-b7ad-9a6e03e03961

STIX ID: report--f8f0cf00-0fba-5633-b7ad-9a6e03e03961

Feed Name: Jamf Blog

Threat Score
80/100

Date Published: 2025-11-25

Date Updated: 2026-07-16

...
...

Jamf Threat Labs details an active FlexibleFerret macOS campaign that uses fake recruitment assessments and Terminal-based social engineering to install a multi-stage loader (JavaScript stagers → macpatch.sh → drivfixer.sh → Go backdoor). The malware establishes persistence via a LaunchAgent, exfiltrates captured credentials to Dropbox, contacts a hard-coded C2 (95.169.180.140:8080), and the report provides file hashes, domains, URLs, and file paths as IoCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.