๐จ New FrigidStealer Malware Targets macOS Users! ๐จ
Cybercriminals are deploying a new macOS info-stealer called FrigidStealer via fake browser update pop-ups! ๐
๐ต๏ธโโ๏ธ Whoโs Behind It?
๐น TA2727 โ A threat actor using fake updates to spread malware ๐ญ
๐น Works with TA2726 (malicious traffic distributor) and TA569 (SocGholish malware)
๐น Active since September 2022, targeting Windows, Android & now macOS
โ ๏ธ How the Attack Works:
๐น Victims visit a compromised website ๐
๐น Fake Chrome/Safari update appears ๐
๐น Users unknowingly install FrigidStealer ๐ฅ๏ธ
๐น Malware harvests passwords, browser data, Apple Notes & crypto wallet info ๐ธ
๐ Technical Details:
๐น Written in Go, using WailsIO project for legitimacy ๐ญ
๐น Bypasses Gatekeeper if users manually approve execution
๐น Uses AppleScript to trick users into entering system passwords ๐
๐ก Stay Safe!
โ
NEVER download browser updates from pop-ups โ
โ
Update browsers only from official sources ๐
โ
Use strong endpoint security & monitoring ๐
#CyberSecurity #macOSMalware #FrigidStealer #FakeUpdates #ThreatIntel
Post #1574
347
- ๐ 2