FrigidStealer

Malware type
credential-stealer, spyware
Profile updated
2026-07-07 14:08:20

Targeted industries: financial-services technology-and-telecommunications

Context

According to Proofpoint, FrigidStealer FrigidStealer uses Apple script files and osascript to prompt the user to enter their password, and then to gather data including browser cookies, files with extensions relevant to password material or cryptocurrency from the victim’s Desktop and Documents folders, and any Apple Notes the user has created.

Reports & references

  • proofpoint.com — Update Fake Updates Two New Actors And New Mac Malware (report)
  • malpedia.caad.fkie.fraunhofer.de — Osx.Frigid Stealer (report)

External references