Skip to main content
Mallory
Back to malware
MalwareUsed by 2 actors

FrigidStealer

FrigidStealer is a macOS information-stealing malware strain, described in the content as part of the Ferret malware family, first reported in February 2025. It is distributed through fake browser or software update prompts embedded in legitimate or compromised websites, including DMG files disguised as Safari updates, and uses social engineering rather than exploits or exploit kits. The lures can be tailored to the victim’s browser, and the installation flow includes instructions that help users bypass macOS Gatekeeper protections, including password prompts and AppleScript-assisted execution. After execution, a Mach-O payload installs the malware; one reported malicious app used the bundle ID com.wails.ddaolimaki-daunito.

Its primary capabilities are credential and data theft from macOS systems. Reported targets include browser cookies, session cookies, stored passwords/browser credentials, cryptocurrency-related files and wallet data, system files, and Apple Notes. The malware has also been described as focusing on browser credentials and session cookies specifically. Exfiltration has been reported via DNS queries routed through macOS mDNSResponder. Additional reported behaviors include registering as a foreground application via launchservicesd, interacting through unauthorized Apple Events, deleting traces of itself after execution, and terminating its own process after exfiltration to reduce detection. Logs from Apple’s Unified Logging System reportedly show use of legitimate process names and services to blend in.

The activity has been linked to threat actors TA2726 and TA2727. Proofpoint assessed TA2726 as likely acting as a traffic distribution service, while TA2727 was observed distributing FrigidStealer and using legitimate websites to deliver scam update alerts; TA2727 was also reported to distribute Windows and Android malware. Observed targeting included macOS devices outside the United States, and separate reporting stated impacts across North America, Europe, and Asia, with infections noted in public-facing industries, particularly retail and hospitality. The campaign creates risk to both personal and enterprise data exposure.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
TA2727

“FrigidStealer malware targets macOS users via fake browser updates, stealing passwords, crypto wallets, and notes using DNS-based data theft methods.”

via hackreadhackread.com
TA2726

“FrigidStealer malware targets macOS users via fake browser updates, stealing passwords, crypto wallets, and notes using DNS-based data theft methods.”

via hackreadhackread.com
MITRE ATT&CK

Techniques & procedures

3 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1204User ExecutionEvidence1
TacticExecution

“If a user clicks the infected update alert, a DMG file automatically downloads… The instructions guide the user through a process that bypasses macOS Gatekeeper… Once executed, a Mach-O executable installs FrigidStealer.”

T1555.003Credentials from Web BrowsersEvidence1

“Once installed, the malware extracts browser cookies, stored passwords…”

Collection

1 technique
T1005Data from Local SystemEvidence1

“the attacker gains access to… files with extensions relevant to password material or cryptocurrency from the victim’s Desktop and Documents folders, and any Apple Notes the user has created”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping3

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.