TF-MAL-osx.frigid_stealer
📛 Threat Title
Malware family: FrigidStealer
Description
ThreatFox malware family `osx.frigid_stealer`. Printable name: FrigidStealer.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cts-tex.com
Understanding the FrigidStealer Cybersecurity Threat In the ever-evolving landscape of cybersecurity, a new threat has emerged that targets macOS users: FrigidStealer . This sophisticated malware is part of a broader campaign orchestrated by a previously unknown threat actor, TA2727. Let's delve into how FrigidStealer works, what it does, and its impact on both personal and business networks.
-
web:cyberdefensewire.com
Campbell, California May 15, 2025 Wazuh, a leader in open source cybersecurity, has released detection capabilities for a recently identified malware strain known as FrigidStealer , a new variant of the MacOS "Ferret" family of malware . FrigidStealer employs deceptive browser update prompts to deceive MacOS users into manually installing a malicious application that bypasses its built-in ...
-
web:cyberinsider.com
Threat actors behind the attack Although FrigidStealer is a new MacOS malware , the infrastructure behind its distribution follows a well-established attack pattern involving two cooperating cybercriminal groups. TA2727 is a financially motivated cybercrime group responsible for delivering FrigidStealer via fake update scams.
-
web:cybersecuritynews.com
A surge in malicious web inject campaigns has introduced FrigidStealer , a new macOS-specific information stealer, deployed via fake browser update prompts.
-
web:dailysecurityreview.com
New MacOS malware , FrigidStealer , uses web injection attacks by cybercriminal groups TA2726 and TA2727, distributing malware based on browser and operating system, bypassing security features.
-
web:jasondeegan.com
Mac users are not immune to cyberattacks, and the emergence of a new malware , FrigidStealer , serves as a stark reminder. According to cybersecurity researchers at Proofpoint, two hacker groups, TA2726 and TA2727, are deploying fake browser updates to ensnare their victims. The goal: to steal sensitive data directly from macOS systems.
-
web:rhisac.org
TA2726 and TA2727 actors operate traffic distribution services (TDS) to redirect users to fake update lures, leading to the installation of malware on Windows, MacOS, and Android devices. A newly discovered MacOS malware , FrigidStealer , was deployed via these campaigns, highlighting the increasing sophistication of threats targeting Apple systems.
-
web:thehackernews.com
That's not all. As of January 2025, the campaign has been updated to target macOS users residing outside of North America by redirecting them to a fake update page that downloaded a new information stealer codenamed FrigidStealer . The FrigidStealer installer, like other macOS malware , requires users to explicitly launch the unsigned app to bypass Gatekeeper protections, following which an ...
-
web:www.bleepingcomputer.com
FrigidStealer targeting macOS FrigidStealer is a Go-based malware built with the WailsIO framework to make the installer appear legitimate so no suspicion is raised during infection. The malware ...
-
web:www.proofpoint.com
Key findings Proofpoint identified and named two new cybercriminal threat actors operating components of web inject campaigns, TA2726 and TA2727. Proofpoint identified a new MacOS malware delivered via web inject campaigns that our researchers called FrigidStealer . The web inject campaign landscape is increasing, with a variety of copycat threat actors conducting similar campaigns, which can ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.