FrigidStealer Explained: macOS Infostealer and Gatekeeper Bypass
ID: 02993008-8a3f-5c47-b1d9-8e54e28aa1c5
STIX ID: report--02993008-8a3f-5c47-b1d9-8e54e28aa1c5
Feed Name: Picus Security Articles
Threat Score
FrigidStealer is a Go-based macOS infostealer (observed January 2025) distributed via fake browser update DMGs served from compromised sites and a TDS; it uses a right-click Gatekeeper bypass and AppleScript/osascript dialogs to phish account passwords, harvest Safari cookies, Apple Notes, and small wallet/password files, and exfiltrate them to a C2 infrastructure attributed to TA2727/TA2726, with recommendations to simulate and validate detections using Picus.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
