FrigidStealer is a macOS information-stealing malware family associated with web-inject and fake browser update campaigns linked to the financially motivated threat clusters TA2726 and TA2727. It is delivered to Mac users through compromised websites and browser-themed fake update lures, including ClickFix-style social engineering and disk image installers that instruct victims to bypass Gatekeeper protections and, in some cases, provide their password through AppleScript-driven prompts. The malware has been described as a Go-based Mach-O binary built with the Wails framework and has also been reported as part of the broader Ferret malware family.
Once executed, FrigidStealer targets high-value user data on macOS systems, including browser credentials, stored passwords, cookies and session material, Apple Notes content, and cryptocurrency-related files. Reporting also indicates collection of browser data from Safari and Chromium-based browsers, along with theft of wallet-related and other sensitive files from common user directories. Some reporting describes DNS-based exfiltration behavior via native macOS networking components, as well as post-execution self-termination and cleanup intended to reduce forensic visibility.
FrigidStealer is part of a broader criminal ecosystem using compromised legitimate websites, traffic distribution services, and fake software update themes to selectively deliver different payloads by geography and platform. In observed campaigns, TA2726 functioned as a traffic broker while TA2727 delivered FrigidStealer to macOS users and other malware families to Windows and Android victims. The malware poses risk to both consumer and enterprise environments because theft of credentials and session artifacts can enable follow-on account compromise, cloud access abuse, and financial theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Its traffic currently also serves TA2727, which delivers different payloads to MacOS users, including FrigidStealer.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon execution, FrigidStealer uses Apple script files and osascript to prompt the user to enter their password, and then to gather data including browser cookies, files with extensions relevant to password material or cryptocurrency from the victim’s Desktop and Documents folders, and any Apple Notes the user has created.
Upon execution, FrigidStealer uses Apple script files and osascript to prompt the user to enter their password, and then to gather data including browser cookies, files with extensions relevant to password material or cryptocurrency from the victim’s Desktop and Documents folders, and any Apple Notes the user has created.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a comparison point for another Mac infostealer known to target browser credentials and Apple Notes.
An information-stealing malware delivered to macOS users via related traffic distribution infrastructure.
FrigidStealer is a stealer payload observed in a MacOS attack chain delivered via TA2726 and TA2727 using ClickFix.
macOS information stealer delivered via fake browser update lures; attributed to TA2727.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.