Odyssey Stealer is a macOS-focused information stealer operated as a malware-as-a-service offering and widely assessed as a rebrand or evolution of Poseidon Stealer, itself derived from Atomic macOS Stealer. It is primarily associated with theft of credentials, browser data, cryptocurrency wallet material, and other high-value user secrets, but multiple analyses also describe botnet-style remote control features that extend it beyond simple one-time collection.
The malware targets browser-stored passwords, cookies, autofill data, Keychain contents, Apple Notes, Telegram data, SSH material, cloud and developer credentials, local files, and extensive cryptocurrency wallet data from both browser extensions and desktop wallet applications. Reported campaigns emphasize cryptocurrency theft, including follow-on replacement of legitimate wallet applications with trojanized versions intended to capture passwords, seed phrases, or transactions.
Odyssey commonly relies on social engineering rather than exploitation. Observed delivery methods include trojanized macOS software packages, fake software updates, fraudulent applications, cracked tools, spoofed developer-tool websites, malicious download portals, and ClickFix or paste-and-run lures that instruct victims to execute attacker-supplied commands in Terminal. Fake installers themed around products such as TradingView, CleanShot, Homebrew, ChatGPT desktop software, and other trusted macOS tools have been used to distribute it. Earlier activity also used DMG-based delivery and user-assisted Gatekeeper bypass patterns; later campaigns increasingly shifted to script-based execution after Apple hardened Gatekeeper-related abuse paths.
Operationally, Odyssey heavily uses AppleScript and shell-based tradecraft to blend with native macOS administration behavior. It has been reported to display fake system or password prompts to capture the user’s macOS password, validate that password locally, and then use it to unlock additional protected data and install persistence. Persistence is typically achieved through launchd mechanisms, including LaunchDaemons or LaunchAgents, enabling continued execution after reboot. Several reports also describe anti-analysis or anti-sandbox checks and per-build or per-infection variation intended to hinder static detection and blocklisting.
Beyond data theft, Odyssey has been described as supporting remote command execution and proxying, with polling-based command-and-control and affiliate-tagged infrastructure consistent with a centrally hosted criminal service. Research into its ecosystem indicates an affiliate model in which operators maintain the panel and backend while affiliates run their own lures and traffic acquisition. Reporting has repeatedly linked its development lineage and operator ecosystem to Russian-speaking cybercrime, though campaign-level attribution should be treated carefully.
Victims have been observed across more than 100 countries, with campaigns affecting individual users, developers, investors, and enterprise macOS users. The malware is especially dangerous in cryptocurrency and developer contexts because it targets wallet software, browser wallet extensions, cloud credentials, SSH keys, and other access material that can enable rapid financial theft or broader compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Odyssey, in essence, is a sophisticated variation or updated iteration of the original Poseidon, designed to operate in the post-Gatekeeper bypass era.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
The sheet was a Google Apps Script web app. The Windows delivery was a signed Microsoft ClickOnce application named GapiUpdate.application.
The campaign reaches victims through deceptive software and update prompts, including ClickFix-style social-engineering lures that persuade users to run malicious commands.
In most scenarios, once users interact with the Fix or Verify button in the lure, the button will covertly copy an obfuscated PowerShell command to the clipboard and present the user with “verification steps.”
Once the fateful paste into a Terminal window took place, the traditional AppleScript stealer code we’ve observed in previous years executed to gather data and exfiltrate.
The main payload is obfuscated AppleScript wrapped in a shell script ... do shell script command_payload
A támadók legitimnek látszó, azonban kártékony kódot tartalmazó szoftvercsomagokkal próbálják megtéveszteni a felhasználókat, köztük TradingView és CleanShot utánzatokkal.
Odyssey Stealer brought with it a host of enhanced capabilities designed specifically to evade detection... These new features included: Anti-sandboxing mechanisms: Tools and logic to detect and avoid execution within analysis environments like virtual machines or emulators.
A fake dialog tricks the user into entering their macOS password ... The password is validated against the system using dscl . authonly
On macOS, this exact trap drops Odyssey Stealer to steal sensitive data.
A kártevő a fertőzött rendszerekről képes lehet a böngészőkben tárolt jelszavak, aktív munkamenet cookie-k és automatikus kitöltési adatok megszerzésére
The researchers found that Odyssey can collect passwords, cookies, and autofill data from widely used browsers...
Odyssey Stealer brought with it a host of enhanced capabilities designed specifically to evade detection... These new features included: Anti-sandboxing mechanisms: Tools and logic to detect and avoid execution within analysis environments like virtual machines or emulators.
Once launched, the malware quietly searches the device for valuable information... By taking wallet data, cloud and developer credentials, messaging-app information, and local system records...
A fake dialog tricks the user into entering their macOS password ... The password is validated against the system using dscl . authonly
Botnet component: Adding functionality for persistent remote execution and control, indicating a move towards more complex capabilities beyond simple, one-time data exfiltration.
supporting arbitrary shell execution, reinfection, and a SOCKS5 proxy for tunneling traffic through victim machines ... enablesocks5 Downloads and runs SOCKS5 proxy
78 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS stealer delivered by the alternate macOS infection chain in the same campaign.
A macOS information-stealing malware that collects credentials, browser data, cryptocurrency wallet data, cloud and developer credentials, messaging-app information, SSH keys, shell history, and other sensitive files. It also establishes persistence via a LaunchDaemon, communicates with command-and-control infrastructure, and has been observed replacing wallet applications with trojanized versions to drain cryptocurrency wallets.
An infostealer delivered via fake ChatGPT desktop app download pages in the LLMShare campaign; it targets macOS users and steals sensitive data.
Information-stealing malware observed being downloaded by the spoofed Homebrew infrastructure as part of the campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.