Poseidon Stealer is a macOS information-stealing malware family derived from Atomic macOS Stealer (AMOS). It became prominent in 2024 and shares substantial AppleScript code and data-collection logic with AMOS. It collects login credentials, private keys, browser cookies, cryptocurrency wallet data, and sensitive information from browser extensions and other applications. Collected data is compressed into a ZIP archive and exfiltrated to attacker-controlled command-and-control infrastructure. Its abuse of built-in AppleScript functionality and user-assisted circumvention of Gatekeeper protections complicates detection and prevention.
Poseidon has been distributed through phishing and malspam, malicious advertising, and counterfeit software-download websites impersonating AI services, VPN providers, and other software brands. A late-June 2024 campaign targeted macOS users in German-speaking Switzerland with emails impersonating AGOV, the Swiss government login service, and offering a malicious disk-image download. Later activity tracked under the Poseidon name used paste-and-run or ClickFix social engineering to induce users to execute malicious commands.
Poseidon's development is associated with the cybercriminal alias Rodrigo4. The platform was subsequently sold and rebranded as Odyssey Stealer, which expanded the lineage with persistence and remote-control capabilities. Those later additions should not be assumed to exist in earlier Poseidon versions. Poseidon Stealer is distinct from the unrelated Poseidon agent for the Mythic command-and-control framework.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the mechanism used in a sample identified as Poseidon stealer ... Malwarebytes mentioned ... “a large part of the code base being the same as its predecessor”, namely Atomic stealer
the mechanism used in a sample identified as Poseidon stealer ... Malwarebytes mentioned ... “a large part of the code base being the same as its predecessor”, namely Atomic stealer
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The malspam emails contain a link to bing.com from which victim gets redirects to another, mostly likely compromised host, that finally redirects the victim to a website hosting Poseidon Stealer.
MITRE ATT&CK Mapping The Backdoor (scan-tron.link targeting Odyssey operators) Tactic Technique ID Initial Access Supply Chain Compromise T1195.002
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS stealer family referenced as the predecessor brand to Odyssey Stealer; described indirectly as part of a lineage stemming from AMOS.
A macOS stealer MaaS family that preceded Odyssey Stealer. The content describes Odyssey as a direct rebrand of Poseidon, sharing delivery, browser and wallet targeting, Keychain theft, LaunchDaemon persistence, and trojanized app replacement.
A macOS stealer focused on obtaining sensitive data from browsers, extensions, and other applications. It relies heavily on AppleScript, previously used Gatekeeper bypass techniques for deployment, and later evolved into Odyssey Stealer.
Information stealer identified as another member of the same malware family as Atomic Stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.