s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.frigid_stealer

📛 Threat Title

Malware family: FrigidStealer

Category: FrigidStealer First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.frigid_stealer`. Printable name: FrigidStealer.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:cts-tex.com

    Understanding the FrigidStealer Cybersecurity Threat In the ever-evolving landscape of cybersecurity, a new threat has emerged that targets macOS users: FrigidStealer . This sophisticated malware is part of a broader campaign orchestrated by a previously unknown threat actor, TA2727. Let's delve into how FrigidStealer works, what it does, and its impact on both personal and business networks.

  • web:cyberdefensewire.com

    Campbell, California May 15, 2025 Wazuh, a leader in open source cybersecurity, has released detection capabilities for a recently identified malware strain known as FrigidStealer , a new variant of the MacOS "Ferret" family of malware . FrigidStealer employs deceptive browser update prompts to deceive MacOS users into manually installing a malicious application that bypasses its built-in ...

  • web:cyberinsider.com

    Threat actors behind the attack Although FrigidStealer is a new MacOS malware , the infrastructure behind its distribution follows a well-established attack pattern involving two cooperating cybercriminal groups. TA2727 is a financially motivated cybercrime group responsible for delivering FrigidStealer via fake update scams.

  • web:cybersecuritynews.com

    A surge in malicious web inject campaigns has introduced FrigidStealer , a new macOS-specific information stealer, deployed via fake browser update prompts.

  • web:dailysecurityreview.com

    New MacOS malware , FrigidStealer , uses web injection attacks by cybercriminal groups TA2726 and TA2727, distributing malware based on browser and operating system, bypassing security features.

  • web:jasondeegan.com

    Mac users are not immune to cyberattacks, and the emergence of a new malware , FrigidStealer , serves as a stark reminder. According to cybersecurity researchers at Proofpoint, two hacker groups, TA2726 and TA2727, are deploying fake browser updates to ensnare their victims. The goal: to steal sensitive data directly from macOS systems.

  • web:rhisac.org

    TA2726 and TA2727 actors operate traffic distribution services (TDS) to redirect users to fake update lures, leading to the installation of malware on Windows, MacOS, and Android devices. A newly discovered MacOS malware , FrigidStealer , was deployed via these campaigns, highlighting the increasing sophistication of threats targeting Apple systems.

  • web:thehackernews.com

    That's not all. As of January 2025, the campaign has been updated to target macOS users residing outside of North America by redirecting them to a fake update page that downloaded a new information stealer codenamed FrigidStealer . The FrigidStealer installer, like other macOS malware , requires users to explicitly launch the unsigned app to bypass Gatekeeper protections, following which an ...

  • web:www.bleepingcomputer.com

    FrigidStealer targeting macOS FrigidStealer is a Go-based malware built with the WailsIO framework to make the installer appear legitimate so no suspicion is raised during infection. The malware ...

  • web:www.proofpoint.com

    Key findings Proofpoint identified and named two new cybercriminal threat actors operating components of web inject campaigns, TA2726 and TA2727. Proofpoint identified a new MacOS malware delivered via web inject campaigns that our researchers called FrigidStealer . The web inject campaign landscape is increasing, with a variety of copycat threat actors conducting similar campaigns, which can ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.