Odyssey Stealer is a macOS information-stealing malware family with persistent remote-access capabilities, distributed through an affiliate-based malware-as-a-service operation. It is a rebrand of Poseidon Stealer, which originated as a fork of Atomic macOS Stealer (AMOS). Its criminal ecosystem uses centrally managed command-and-control infrastructure and an administrative panel providing payload building, compromised-device management, and stolen-data access. It targets individuals and corporate Mac users worldwide, particularly cryptocurrency users, and supports Intel and Apple silicon systems.
Odyssey commonly executes through obfuscated AppleScript and native macOS utilities. Delivery mechanisms include ClickFix prompts, fake CAPTCHA verification pages, counterfeit software installers, fraudulent updates, cracked tools, phishing, and malicious advertisements. Impersonated applications and services include Homebrew, TradingView, CleanShot, and ChatGPT. These lures persuade users to install malicious software or paste attacker-supplied commands into Terminal rather than relying on exploitation of a macOS vulnerability.
The malware presents a fake authentication dialog, captures and validates the victim’s macOS password, and steals Keychain contents. It collects browser passwords, session cookies, autofill and payment data, cryptocurrency wallet files, private keys, seed phrases, browser-extension data, messaging-account information, sensitive documents, SSH keys, and cloud and developer credentials. Collected information is archived and uploaded to attacker-controlled servers, with retry logic for failed transfers. Some variants replace legitimate Ledger, Trezor, and Exodus applications with trojanized versions to intercept credentials and facilitate cryptocurrency theft.
Odyssey establishes persistence through macOS LaunchDaemons and polls its command-and-control infrastructure for instructions. Its remote-access component supports arbitrary shell execution, reinfection, and SOCKS5 proxying through compromised hosts. Anti-sandbox checks and obfuscated scripts impede analysis. The malware’s lineage is associated with the Poseidon developer known as Rodrigo4, but definitive attribution of current operations to a particular operator or state sponsor is not established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Odyssey, in essence, is a sophisticated variation or updated iteration of the original Poseidon, designed to operate in the post-Gatekeeper bypass era.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
The sheet was a Google Apps Script web app. The Windows delivery was a signed Microsoft ClickOnce application named GapiUpdate.application.
The site then instructs macOS users to copy and paste a Base64-encoded command into their terminal.
In most scenarios, once users interact with the Fix or Verify button in the lure, the button will covertly copy an obfuscated PowerShell command to the clipboard and present the user with “verification steps.”
Odyssey Stealer brought with it a host of enhanced capabilities designed specifically to evade detection... These new features included: Anti-sandboxing mechanisms: Tools and logic to detect and avoid execution within analysis environments like virtual machines or emulators.
On macOS, this exact trap drops Odyssey Stealer to steal sensitive data.
A kártevő a fertőzött rendszerekről képes lehet a böngészőkben tárolt jelszavak, aktív munkamenet cookie-k és automatikus kitöltési adatok megszerzésére
A kártevő a fertőzött rendszerekről képes lehet a böngészőkben tárolt jelszavak... megszerzésére... A kártevő emellett célba veszi a macOS Keychain tartalmát
Containing the username, password keychain, hardware details, and other browser-related information.
The researchers found that Odyssey can collect passwords, cookies, and autofill data from widely used browsers...
Odyssey Stealer brought with it a host of enhanced capabilities designed specifically to evade detection... These new features included: Anti-sandboxing mechanisms: Tools and logic to detect and avoid execution within analysis environments like virtual machines or emulators.
Once launched, the malware quietly searches the device for valuable information... By taking wallet data, cloud and developer credentials, messaging-app information, and local system records...
105 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS information-stealing malware discussed in connection with C2 infrastructure, cryptocurrency-wallet replacement, and malicious DMG delivery artifacts.
macOS stealer delivered by the alternate macOS infection chain in the same campaign.
A macOS information-stealing malware that collects credentials, browser data, cryptocurrency wallet data, cloud and developer credentials, messaging-app information, SSH keys, shell history, and other sensitive files. It also establishes persistence via a LaunchDaemon, communicates with command-and-control infrastructure, and has been observed replacing wallet applications with trojanized versions to drain cryptocurrency wallets.
An infostealer delivered via fake ChatGPT desktop app download pages in the LLMShare campaign; it targets macOS users and steals sensitive data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.