Malware News New FrigidStealer infostealer infects Macs via fake browser updates

Gandalf_The_Grey

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
7,606
The FakeUpdate malware campaigns are increasingly becoming muddled, with two additional cybercrime groups tracked as TA2726 and TA2727, running campaigns that push a new macOS infostealer malware called FrigidStealer.

The new malware is delivered to Mac users, but the same campaign also uses Windows and Android payloads to cover a broad range of targets.

The new campaign was discovered by researchers at Proofpoint, who note that malicious JavaScript to display fake browser update messages is being adopted by a rising number of threat actors, making tracking and analysis increasingly tricky.

In this campaign, TA2726 and TA2727 work together, with the former acting as the traffic distributor and facilitator and the latter as the malware distributor.

TA2726 has been active since at least September 2022, selling traffic to other cybercriminals. It often leverages Keitaro TDS, a widely abused legitimate traffic distribution service.

TA2727 is a financially motivated threat group first identified in January 2025, deploying Lumma Stealer for Windows, Marcher for Android, and FrigidStealer for macOS.
To stay clear from infostealer infections, do not ever execute any commands or downloads prompted by websites, especially those pretending to be fixes, updates, or captchas.

For those who become infected with infostealers, you must change the passwords at every site you have an account, especially if you use the same password at multiple sites.
 
  • Like
Reactions: harlan4096

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top