Poseidon Stealer is a macOS-focused information stealer that emerged in 2024 and became one of the more prominent malware families targeting Apple systems. It is closely related to Atomic macOS Stealer (AMOS), sharing substantial code and tradecraft, particularly heavy use of AppleScript to collect data from browsers, extensions, and other applications. Security reporting indicates the malware was active through 2024 and early 2025 before being sold and later rebranded as Odyssey Stealer.
Poseidon Stealer is designed to harvest sensitive information from infected Macs, including login credentials, browser cookies, private keys, and cryptocurrency wallet data. It searches the host for valuable information, stages stolen material into compressed archives, and exfiltrates the results to attacker-controlled infrastructure. Reporting also associates the family with theft from browser- and wallet-related data stores and broader collection from user applications commonly used to store secrets or financial information.
Observed delivery methods include phishing and malspam campaigns as well as fake software-download websites. In a notable campaign targeting German-speaking Switzerland in late June 2024, operators impersonated AGOV, the Swiss public-service login platform, to lure macOS users into downloading a malicious disk image. Separate reporting links Poseidon Stealer to phony websites impersonating AI tools, VPN services, and other well-known software brands. Later activity tied to this malware family also reflects a shift in the broader macOS stealer ecosystem toward paste-and-run and ClickFix-style social engineering after Apple closed a widely abused Gatekeeper bypass in October 2024, though some post-sale activity may overlap with Odyssey rather than original Poseidon operations.
Poseidon Stealer is part of a broader surge in enterprise-relevant macOS malware. It has been tracked alongside Atomic Stealer and other macOS stealers as adversaries increasingly target Apple devices for credential theft, session theft, and cryptocurrency-related data. The malware’s reliance on native macOS scripting and trusted system components complicates detection and contributes to overlap in telemetry with related families. Available reporting indicates that after completing theft, the malware may remain on disk but not continue executing after a system restart in at least some observed variants or campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the mechanism used in a sample identified as Poseidon stealer ... Malwarebytes mentioned ... “a large part of the code base being the same as its predecessor”, namely Atomic stealer
the mechanism used in a sample identified as Poseidon stealer ... Malwarebytes mentioned ... “a large part of the code base being the same as its predecessor”, namely Atomic stealer
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The malspam emails contain a link to bing.com from which victim gets redirects to another, mostly likely compromised host, that finally redirects the victim to a website hosting Poseidon Stealer.
MITRE ATT&CK Mapping The Backdoor (scan-tron.link targeting Odyssey operators) Tactic Technique ID Initial Access Supply Chain Compromise T1195.002
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS stealer family referenced as the predecessor brand to Odyssey Stealer; described indirectly as part of a lineage stemming from AMOS.
A macOS stealer MaaS family that preceded Odyssey Stealer. The content describes Odyssey as a direct rebrand of Poseidon, sharing delivery, browser and wallet targeting, Keychain theft, LaunchDaemon persistence, and trojanized app replacement.
A macOS stealer focused on obtaining sensitive data from browsers, extensions, and other applications. It relies heavily on AppleScript, previously used Gatekeeper bypass techniques for deployment, and later evolved into Odyssey Stealer.
Information stealer identified as another member of the same malware family as Atomic Stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.