Poseidon is an open-source, Go-based remote-access and post-exploitation agent for the Mythic command-and-control framework. It runs on macOS and Linux and has been deployed as a backdoor in espionage and software supply-chain attacks. It is distinct from the macOS infostealer also called Poseidon and the Windows point-of-sale malware PoSeidon.
Poseidon supports remote shell execution, file upload and download, screenshot capture, keylogging, clipboard monitoring, process and directory enumeration, environment-variable manipulation, port scanning, SSH credential testing, and SOCKS proxying. It collects host information during its initial command-and-control check-in and can search for and exfiltrate SSH keys and AWS credentials. macOS variants support persistence through LaunchAgents, LaunchDaemons, and login items.
The CrateDepression supply-chain campaign delivered Poseidon through a typosquatted Rust dependency that selectively activated in GitLab continuous-integration environments, targeting Linux and macOS development systems. Transparent Tribe, also known as APT36, has deployed Poseidon against Indian government personnel using UNIX-based systems, with phishing lures and an ELF-wrapped Python downloader preceding the agent. Poseidon has also been used for macOS post-exploitation in the DPRK-linked TraderTraitor intrusion involving a Safe{Wallet} developer. Because the agent is publicly available, its presence alone does not establish attribution to any particular threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“After gaining initial access to the developer's machine, attackers deployed MythicC2's Poseidon agent, a robust Golang-based payload offering advanced stealth and extensive post-exploitation capabilities for macOS environments.”
Помимо Crimson RAT, в арсенал APT36 входят DeskRAT, AresRAT, AllaKore, GetaRAT и Poseidon.
The threat actor rebranded the new project ‘Poseidon’ and added a few new features such as looting VPN configurations.
We observed that Mythic Agents had been utilized by the APT-36 group in their operations. One such Agent is “Poseidon.”
this report explains the usage of Poseidon malware which targets government employees who use UNIX-based systems for their jobs ... The 2nd stage file is defined as a payload named Poseidon, written in Go programming language and included in the MythicAgents project on GitHub.
40 distinct techniques documented for this family, organized by ATT&CK tactic.
People who clicked on the ad were redirected to arc-download[.]com, a completely fake site offering Arc for Mac only.
attackers need to take advantage of techniques more similar to those we see in Windows systems, such as Cron Jobs
The first ELF file detected in the attack campaign is the Python script file wrapped in ELF format... By extracting the compiled Python file (Kavach.pyc)... it becomes clear to understand the purpose of the 1st stage file.
The service consists of a malware panel with statistics and a builder with custom name, icon and AppleScript.
attackers need to take advantage of techniques more similar to those we see in Windows systems, such as Cron Jobs
case 42 : //Execute persist_launch command to install launchd //persistence go persist_launchd.Run ( task )
attackers need to take advantage of techniques more similar to those we see in Windows systems, such as Cron Jobs
An embedded PE is extracted through shellcode and execution continues with the embedded binary.
case 42 : //Execute persist_launch command to install launchd //persistence go persist_launchd.Run ( task )
The downloaded DMG file resembles what one would expect when installing a new Mac application with the exception of the right-click to open trick to bypass security protections.
An embedded PE is extracted through shellcode and execution continues with the embedded binary.
There is a new malware family targeting PoS systems, infecting machines to scrape memory for credit card information and exfiltrate that data to servers.
The downloaded binary, FindStr, installs a keylogger and scans the memory of the PoS device for number sequences that could be credit card numbers.
case 17 : // Test credentials against remote hosts go sshauth.Run ( task )
Armed with the developer's AWS access key ID, secret key, and temporary session token, the threat actors then authenticated into Safe{Wallet}'s AWS environment.
The script copied and exfiltrated a number of items, among which were any SSH keys located on the victims’ device.
The stealer offers functionalities reminescent of Atomic Stealer including: file grabber, crypto wallet extractor, password manager (Bitwarden, KeePassXC) stealer, and browser data collector.
case 25 : // Retrieve information about the current user. go getuser.Run ( task )
case 18 : // Scan ports on remote hosts. go portscan.Run ( task )
The PE then cycles through all running processes on the PoS device to look for processes with a security token not associated with the “NT AUTHORITY” domain name.
The stealer offers functionalities reminescent of Atomic Stealer including: file grabber, crypto wallet extractor, password manager (Bitwarden, KeePassXC) stealer, and browser data collector.
There is a new malware family targeting PoS systems, infecting machines to scrape memory for credit card information and exfiltrate that data to servers.
Credit card numbers and keylogger data is sent to the exfiltration server after being XORed and base64 encoded.
The malware used in the campaign is trying to send data to the remote server with a POST request by establishing a TCP connection with the IP address 70.34.214[.]252.
168 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Вредоносный инструмент, названный частью ротируемого инструментария APT36; назначение в материале не уточняется.
Named as a RAT among the malware/tools detected in the incident context.
Referenced as an example of existing macOS malware in background context only.
C2 agent referenced as an example of an already-deployed implant on a target macOS host.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.