TecnoArtesanos Tech BlogTecnoArtesanos Tech Blog

Blog

0
admin
Tuesday, 18 February 2025 / Published in Uncategorized

New Mac Malware Poses as Browser Updates

A new macOS malware called FrigidStealer is spreading through fake browser update alerts, allowing attackers to steal sensitive data, according to research from Proofpoint. This sophisticated campaign, embedded in legitimate sites, tricks users into bypassing macOS security measures. Once installed, the malware extracts browser cookies, stored passwords, cryptocurrency-related files, and Apple Notes – potentially exposing both personal and enterprise data.

Contents
  • Fake updates trick Mac users into bypassing security
    • Must-read security coverage
  • How to defend against web inject campaigns
  • macOS threats are escalating

The two newly identified threat actors operate parts of these web-inject campaigns:

  • TA2726, which may act as a traffic distribution service for other threat actors.
  • TA2727, a group that distributes FrigidStealer and malware for Windows and Android. They may use fake update alerts to enable malware and are identifiable by their use of legitimate websites to send scam update alerts.

Both threat actors sell traffic and distribute malware.

Patrocinado por TecnoArtesanos ¿Tu empresa ya está usando IA? Automatizamos procesos, integramos asistentes inteligentes y conectamos tus sistemas. Descubre cómo →

Fake updates trick Mac users into bypassing security

The update scam includes deceptive instructions designed to help attackers evade macOS security measures.

At the end of January 2025, Proofpoint found that TA2727 used scam update alerts to place information-stealing malware on macOS devices outside of the United States. The campaign embeds fake “Update” buttons on otherwise secure websites, making it appear as though a routine browser update is required. These fake updates can be delivered through Safari or Chrome.

If a user clicks the infected update alert, a DMG file automatically downloads. The malware detects the victim’s browser and displays customized, official-looking instructions and icons that make the download appear legitimate.

The instructions guide the user through a process that bypasses macOS Gatekeeper, which would normally warn the user about installing an untrusted application. Once executed, a Mach-O executable installs FrigidStealer.

Right-clicking bypasses MacOS Gatekeeper.
Right-clicking bypasses MacOS Gatekeeper. Image: Proofpoint

If users enter their password during the process, the attacker gains access to “browser cookies, files with extensions relevant to password material or cryptocurrency from the victim’s Desktop and Documents folders, and any Apple Notes the user has created,” ProofPoint said.

SEE: This checklist contains everything employers need to vet employees for security-sensitive tasks.

Must-read security coverage

How to defend against web inject campaigns

Because attackers may distribute this malware through legitimate websites, security teams may struggle to detect and mitigate the threat. However, Proofpoint recommends the following best practices to strengthen defenses:

  • Implement endpoint protection and network detection tools, such as Proofpoint’s Emerging Threats ruleset.
  • Train users to identify how the attack works and report suspicious activity to their security teams. Integrate knowledge about these scams into existing security awareness training.
  •  Restrict Windows users from downloading script files and opening them in anything other than a text file. This can be configured via Group Policy settings.

macOS threats are escalating

In January 2025, SentinelOne observed a rise in attacks targeting macOS devices in enterprises. Additionally, more threat actors are adopting cross-platform development frameworks to create malware that works across multiple operating systems.

“These trends suggest a deliberate effort by attackers to scale their operations while exploiting gaps in macOS defenses that are often overlooked in enterprise environments,” wrote Phil Stokes, a threat researcher at SentinelOne.

¿Quieres aplicar esto en tu empresa?

En TecnoArtesanos desarrollamos software, integramos IA y creamos experiencias digitales para negocios que quieren crecer.

Conversemos Nuestros servicios

¿Te gustó este artículo? Síguenos en Facebook para más contenido como este.

What you can read next

Build Smarter Business Plans with LivePlan
Apple Passwords App Vulnerability Exposed Users for Months
México creará su propio lenguaje de IA con apoyo de Nvidia

Tecnología hecha a mano para tu negocio

Software, IA, sitios web y diseño. Hablemos de tu proyecto.

¿Hablamos? Síguenos en Facebook →

Recent Posts

  • ¿Quién responde por el algoritmo que recluta jóvenes para el crimen organizado?
  • InSpace: experiencias inmersivas en CDMX para eventos y lanzamientos
  • Dots vs. Muse: La batalla de los agentes personales de IA ha comenzado
  • Desconexión selectiva: la IA como el nuevo “Do Not Disturb”
  • Los padrinos de la IA advierten sobre una “explosión de inteligencia” que podría escapar al control humano

Recent Comments

  1. A WordPress Commenter on Welcome to My Tech Blog – A New Chapter in Innovation

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • August 2016

Categories

  • Uncategorized

Recent Posts

  • ¿Quién responde por el algoritmo que recluta jóvenes para el crimen organizado?

    Bajar o eliminar contenidos cuando las autorida...
  • InSpace: experiencias inmersivas en CDMX para eventos y lanzamientos

    A estas alturas es imposible pensar que la tecn...
  • Dots vs. Muse: La batalla de los agentes personales de IA ha comenzado

    Ayer pasé la mañana en el DevDay anual de OpenA...
  • Desconexión selectiva: la IA como el nuevo “Do Not Disturb”

    Piensa en el grupo de WhatsApp de la familia o ...
  • Los padrinos de la IA advierten sobre una “explosión de inteligencia” que podría escapar al control humano

    La humanidad podría estar a punto de experiment...

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • August 2016

Categories

  • Uncategorized
TOP
TecnoArtesanos

Un estudio boutique que crea experiencias digitales: desarrollo de software, inteligencia artificial y soluciones en la nube, con el cuidado de la joyería fina.

¿Hablamos?

Servicios

  • Desarrollo de software
  • Integración de IA
  • Experiencias digitales
  • Redes sociales y diseño

TecnoArtesanos

  • Inicio
  • Portafolio
  • Nosotros
  • Blog

Contacto

  • +506 8730-7941
  • [email protected]
  • WhatsApp
  • Facebook
© 2026 TecnoArtesanos. Todos los derechos reservados. tecnoartesanos.com
TecnoArtesanos — Software a la medida, IA y sitios web para tu negocio. Conoce nuestros servicios →
✦ TecnoArtesanos

¿Te interesa llevar esto a tu negocio?

Escribimos sobre tecnología porque la construimos. Si tienes un proyecto en mente, conversemos: la primera llamada no tiene costo.

  • Desarrollo de software a la medida
  • Integración de inteligencia artificial
  • Sitios web y experiencias digitales
  • Redes sociales y diseño gráfico
¿Hablamos? Ver servicios

¿Prefieres WhatsApp? +506 8730-7941 · Síguenos en Facebook