FrigidStealer Malware Emerges, Harvesting Login Credentials from macOS Systems

FrigidStealer Malware Emerges, Harvesting Login Credentials from macOS Systems

FrigidStealer: A Covert macOS Threat Exploiting Trust and Evading Detection

In early 2025, a new cyber threat emerged—FrigidStealer, a stealthy malware campaign designed to infiltrate macOS devices and siphon off sensitive user data under the guise of system legitimacy. This advanced strain doesn’t just sneak past defenses—it manipulates user behavior to gain privileged access, marking a concerning evolution in macOS-targeted threats.

Weaponizing Familiarity: The Trojan Update Gambit

Rather than relying on conventional exploits, FrigidStealer leverages social engineering with a twist: it hijacks trust in browser update notifications. By deploying fake update prompts on compromised websites, attackers persuade users to download a seemingly innocuous disk image (.DMG). Manual execution is required—a critical move that shifts the burden of permission to the user, circumventing built-in protections like Gatekeeper.

Once launched, FrigidStealer prompts for the user’s password using AppleScript, mimicking legitimate system requests. This grants the malware root-level privileges—an open door to the system’s most sensitive assets.

Behind the Mask: How FrigidStealer Hides in Plain Sight

Post-installation, the malware embeds itself into the system as an application named “ddaolimaki-daunito”, masquerading as Safari Updater.app within the Volumes directory. The deceptive filename and location play a key role in avoiding user suspicion.

It persists by registering with launchservicesd under a seemingly harmless bundle ID: com.wails.ddaolimaki-daunito. Running as a foreground application cloaked as a system utility, FrigidStealer can endure system reboots while blending in with legitimate processes.

Stealing in Silence: Data Extraction via Apple Events and DNS

FrigidStealer is engineered for quiet theft. It uses Apple Events, macOS’s native inter-process communication mechanism, to access browser-stored credentials, configuration files, and filesystem data—all without raising security alarms.

What sets FrigidStealer apart is its use of DNS-based exfiltration through the mDNSResponder service. This covert channel disguises outbound data as routine DNS queries, effectively slipping past standard network defenses. An example detection pattern is:

Once the heist is complete, the malware shuts down its core processes, erasing evidence of its activity and complicating forensic recovery efforts.

Criminal Origins and Real-World Risk

Analysis by Wazuh threat researchers suggests possible ties between FrigidStealer and the infamous EvilCorp cybercrime group, indicating that this operation isn’t just sophisticated—it’s well-funded. The malware’s objectives include harvesting login credentials, cryptocurrency wallet data, and other high-value digital assets, posing serious risks of identity theft and financial exploitation.

Defending Against FrigidStealer

Given its evasive tactics and macOS-specific targeting, traditional security tools may fall short. Experts recommend:

  • Deploying advanced endpoint protection built specifically for macOS
  • Educating users to distrust browser-based update prompts
  • Leveraging behavior-based detection platforms like Wazuh, which can flag anomalies tied to FrigidStealer’s signature techniques

As FrigidStealer continues to evolve, staying proactive is the only defense against its sophisticated deception.

More Articles & Posts