Poseidon is a name used for multiple distinct malware families and implants, most notably a Mythic C2 agent for macOS and Linux, a macOS infostealer, and an older point-of-sale malware family often stylized as PoSeidon. The most consistently supported usage in recent operations refers to the Go-based Poseidon agent included in the open-source Mythic framework. In that role, Poseidon functions as a cross-platform post-exploitation backdoor used after initial compromise, especially against macOS and UNIX-like environments. Reported capabilities include host profiling, shell execution, file upload and download, screenshot capture, clipboard monitoring, keylogging, process and directory listing, SOCKS proxying, SSH credential testing, port scanning, persistence-related actions, and exfiltration of sensitive material such as SSH keys and cloud-related secrets. It has been observed in supply-chain and phishing-led intrusions, including campaigns targeting developers and government personnel, and has been used by groups including Transparent Tribe/APT36 in operations against Indian government and defense-related targets.
A separate and unrelated malware family also called Poseidon has been tracked as a macOS stealer. That variant has been described as a rebranded successor to RodStealer and as a competitor to Atomic Stealer. It targets browser data, cryptocurrency wallets, password managers, VPN configurations, and other user data, and has been delivered through malvertising and fake software download pages aimed at macOS users.
The name PoSeidon has also historically referred to Windows point-of-sale malware that scraped payment card data from memory, logged keystrokes, established persistence, and exfiltrated stolen payment information for monetization.
Because the same name is used for materially different malware, attribution and classification should be handled carefully. When referenced in contemporary macOS and Linux intrusion reporting, Poseidon most often denotes the Mythic agent rather than the macOS stealer or the legacy PoS malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The threat actor rebranded the new project ‘Poseidon’ and added a few new features such as looting VPN configurations.
We observed that Mythic Agents had been utilized by the APT-36 group in their operations. One such Agent is “Poseidon.”
this report explains the usage of Poseidon malware which targets government employees who use UNIX-based systems for their jobs ... The 2nd stage file is defined as a payload named Poseidon, written in Go programming language and included in the MythicAgents project on GitHub.
this report explains the usage of Poseidon malware which targets government employees who use UNIX-based systems for their jobs ... The 2nd stage file is defined as a payload named Poseidon, written in Go programming language and included in the MythicAgents project on GitHub.
After gaining initial access to the developer's machine, attackers deployed MythicC2's Poseidon agent, a robust Golang-based payload offering advanced stealth and extensive post-exploitation capabilities for macOS environments.
38 distinct techniques documented for this family, organized by ATT&CK tactic.
People who clicked on the ad were redirected to arc-download[.]com, a completely fake site offering Arc for Mac only.
attackers need to take advantage of techniques more similar to those we see in Windows systems, such as Cron Jobs
The first ELF file detected in the attack campaign is the Python script file wrapped in ELF format... By extracting the compiled Python file (Kavach.pyc)... it becomes clear to understand the purpose of the 1st stage file.
attackers need to take advantage of techniques more similar to those we see in Windows systems, such as Cron Jobs
case 42 : //Execute persist_launch command to install launchd //persistence go persist_launchd.Run ( task )
attackers need to take advantage of techniques more similar to those we see in Windows systems, such as Cron Jobs
An embedded PE is extracted through shellcode and execution continues with the embedded binary.
case 42 : //Execute persist_launch command to install launchd //persistence go persist_launchd.Run ( task )
На практике для обхода XProtect хватает двух: шифрование строк (характерные user-agent, URL-паттерны) и пересборка из исходников с рефакторингом структуры бинаря
The downloaded DMG file resembles what one would expect when installing a new Mac application with the exception of the right-click to open trick to bypass security protections.
There is a new malware family targeting PoS systems, infecting machines to scrape memory for credit card information and exfiltrate that data to servers.
The downloaded binary, FindStr, installs a keylogger and scans the memory of the PoS device for number sequences that could be credit card numbers.
case 17 : // Test credentials against remote hosts go sshauth.Run ( task )
The script copied and exfiltrated a number of items, among which were any SSH keys located on the victims’ device.
The stealer offers functionalities reminescent of Atomic Stealer including: file grabber, crypto wallet extractor, password manager (Bitwarden, KeePassXC) stealer, and browser data collector.
case 25 : // Retrieve information about the current user. go getuser.Run ( task )
case 18 : // Scan ports on remote hosts. go portscan.Run ( task )
The PE then cycles through all running processes on the PoS device to look for processes with a security token not associated with the “NT AUTHORITY” domain name.
The stealer offers functionalities reminescent of Atomic Stealer including: file grabber, crypto wallet extractor, password manager (Bitwarden, KeePassXC) stealer, and browser data collector.
There is a new malware family targeting PoS systems, infecting machines to scrape memory for credit card information and exfiltrate that data to servers.
Credit card numbers and keylogger data is sent to the exfiltration server after being XORed and base64 encoded.
168 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a RAT among the malware/tools detected in the incident context.
Referenced as an example of existing macOS malware in background context only.
C2 agent referenced as an example of an already-deployed implant on a target macOS host.
A macOS infostealer associated with deceptive DMG-based installers that socially engineer users into bypassing Gatekeeper in order to steal credentials, cookies, authentication tokens, and cryptocurrency wallet data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.