logo

FrigidStealer Explained: macOS Infostealer and Gatekeeper Bypass

ID: 02993008-8a3f-5c47-b1d9-8e54e28aa1c5

STIX ID: report--02993008-8a3f-5c47-b1d9-8e54e28aa1c5

Feed Name: Picus Security Articles

Threat Score
72/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

Author: [email protected] (Umut Bayram)

...
...

FrigidStealer is a Go-based macOS infostealer (observed January 2025) distributed via fake browser update DMGs served from compromised sites and a TDS; it uses a right-click Gatekeeper bypass and AppleScript/osascript dialogs to phish account passwords, harvest Safari cookies, Apple Notes, and small wallet/password files, and exfiltrate them to a C2 infrastructure attributed to TA2727/TA2726, with recommendations to simulate and validate detections using Picus.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.