{"id":4035,"date":"2025-05-17T10:03:41","date_gmt":"2025-05-17T10:03:41","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/05\/17\/new-frigidstealer-malware-attacking-macos-users-to-steal-login-credentials\/"},"modified":"2025-05-17T10:03:41","modified_gmt":"2025-05-17T10:03:41","slug":"new-frigidstealer-malware-attacking-macos-users-to-steal-login-credentials","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/05\/17\/new-frigidstealer-malware-attacking-macos-users-to-steal-login-credentials\/","title":{"rendered":"New FrigidStealer Malware Attacking macOS Users to Steal Login Credentials"},"content":{"rendered":"<p>    New FrigidStealer Malware Attacking macOS Users to Steal Login Credentials<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>FrigidStealer, a sophisticated information-stealing malware that emerged in January 2025, is actively targeting macOS endpoints to steal sensitive user data through deceptive tactics.<\/p>\n<p>Unlike traditional malware, FrigidStealer exploits user trust in routine software updates, making it particularly insidious.<\/p>\n<p>The malware has raised significant concerns among cybersecurity experts due to its ability to bypass standard security measures while harvesting valuable personal information from unsuspecting users.<\/p>\n<p>The attack vector relies on social engineering techniques, specifically distributing malicious code via fake browser update pages hosted on compromised websites.<\/p>\n<p>Users are tricked into downloading a malicious disk image file (DMG) that requires manual execution.<\/p>\n<p>Once initiated, the malware bypasses macOS Gatekeeper protections by cleverly prompting users to enter their password via AppleScript, granting it elevated privileges on the system.<\/p>\n<p>Wazuh analysts <a href=\"https:\/\/wazuh.com\/blog\/detecting-frigidstealer-malware-with-wazuh\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the malware\u2019s sophisticated operational mechanics during their recent investigation of emerging threats to macOS environments.<\/p>\n<p>Their research revealed that FrigidStealer\u2019s financial motivations are potentially linked to the notorious EvilCorp syndicate, underscoring its serious threat to both individual users and enterprises.<\/p>\n<p>The stolen data includes credentials and <a href=\"https:\/\/cybersecuritynews.com\/cryptocore-cryptocurrency-scam-draining-wallets\/\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency wallets<\/a>, posing significant risks of identity theft and financial fraud.<\/p>\n<p>Upon execution, the malware registers itself as an application named \u201cddaolimaki-daunito\u201d on the macOS endpoint, with the executable path typically located at \u201cVolumes\/Safari Updater\/Safari Updater.app.\u201d<\/p>\n<p>This deceptive naming convention further enhances its ability to remain undetected by casual users who might mistake it for <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-exploiting-legitimate-software\/\" target=\"_blank\" rel=\"noreferrer noopener\">legitimate software<\/a> components.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Persistence Mechanism and Data Exfiltration<\/strong><\/h2>\n<p>FrigidStealer establishes persistence through sophisticated techniques that ensure it remains operational across system restarts.<\/p>\n<p>The malware leverages launchservicesd as a foreground application with bundle ID \u201ccom.wails.ddaolimaki-daunito\u201d to maintain its presence on infected systems.<\/p>\n<p>This <a href=\"https:\/\/cybersecuritynews.com\/detecting-and-responding-to-new-nation-state-persistence-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistence<\/a> strategy is particularly effective as it mimics legitimate system processes.<\/p>\n<p>The data exfiltration process involves using Apple Events for unauthorized inter-process communication to target sensitive information.<\/p>\n<p>This technique allows the <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> to access browser credentials, filesystem data, and system configuration details without triggering standard security alerts.<\/p>\n<p>A sample of the malware\u2019s execution can be detected through the following command pattern:-<\/p>\n<pre class=\"wp-block-code\"><code># Detection of FrigidStealer DNS exfiltration\n\n  macOS_mDNSResponder\n  (?i)(DNSServiceQueryRecord).*mask.hash: '(S+)'.*pid:(d+).*((.+))\n  program_type,hash,pid,process_name<\/code><\/pre>\n<p>After successfully harvesting credentials and other valuable data, FrigidStealer exfiltrates the stolen information to command-and-control servers through DNS data exfiltration via the mDNSResponder process.<\/p>\n<p>This technique is particularly insidious as it disguises malicious traffic as legitimate DNS queries, making detection challenging through conventional network <a href=\"https:\/\/cybersecuritynews.com\/postgresql-monitoring-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">monitoring tools<\/a>.<\/p>\n<p>Following successful exfiltration, the malware terminates its main process to eliminate traces of its operation, further complicating forensic analysis.<\/p>\n<p>As this threat continues to evolve, cybersecurity experts recommend implementing comprehensive endpoint protection specifically designed for macOS environments, maintaining vigilance regarding software update prompts, and utilizing specialized detection tools like Wazuh that can identify the unique behavioral patterns associated with FrigidStealer infections.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong><code>How SOC Teams Save Time and Effort with ANY.RUN -\u00a0<a href=\"https:\/\/anyrun.webinargeek.com\/how-soc-teams-save-time-and-effort-with-any-run-action-plan?cst=li_csn\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Live webinar for SOC teams and managers<\/a><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-frigidstealer-malware-attacking-macos-users\/\">New FrigidStealer Malware Attacking macOS Users to Steal Login Credentials<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-frigidstealer-malware-attacking-macos-users\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New FrigidStealer Malware Attacking macOS Users to Steal Login Credentials FrigidStealer, a sophisticated information-stealing malware that emerged in January 2025, is actively targeting macOS endpoints to steal sensitive user data through deceptive tactics. Unlike traditional malware, FrigidStealer exploits user trust in routine software updates, making it particularly insidious. The malware has raised significant concerns among [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,258,649],"tags":[130],"class_list":["post-4035","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-malware","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4035"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4035"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4035\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4035"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4035"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4035"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}