Odyssey Stealer is a macOS-focused information stealer operated as a malware-as-a-service offering and widely assessed to be a rebrand or evolution of Poseidon Stealer, itself closely related to Atomic macOS Stealer. It targets Apple systems worldwide and is primarily associated with theft of browser credentials, cookies, autofill data, Keychain material, cryptocurrency wallet data, SSH keys, cloud and developer credentials, messaging application data, and selected local files. The malware has been observed targeting both browser-based wallet extensions and desktop cryptocurrency wallet applications, reflecting a strong emphasis on cryptocurrency theft.
Odyssey commonly relies on social engineering rather than exploitation of a macOS vulnerability. Observed delivery methods include fake software updates, fraudulent applications, cracked software, spoofed developer-tool websites such as counterfeit Homebrew pages, malicious ads leading to fake download portals, and ClickFix-style paste-and-run lures that instruct victims to execute attacker-supplied commands in Terminal. AppleScript-heavy execution is a recurring trait, helping the malware blend with legitimate macOS automation behavior.
Once executed, Odyssey collects data from Chromium-based browsers, Firefox-family browsers, Safari, Keychain, Notes, Telegram Desktop, and wallet software. It has also been reported to prompt victims for their macOS password using deceptive dialogs, enabling access to protected secrets and facilitating deeper compromise. Beyond one-time theft, Odyssey can establish persistence through launchd mechanisms, including LaunchDaemon installation, and maintain command-and-control communications with primary and fallback infrastructure.
Odyssey is notable for extending beyond classic infostealer behavior. Multiple analyses describe remote-access functionality including arbitrary shell execution, reinfection, and proxying through compromised hosts, making it stealer-plus-RAT tradecraft rather than a simple grab-and-go collector. It has also been observed replacing legitimate cryptocurrency wallet applications with trojanized versions intended to intercept credentials, seed phrases, or transactions and drain assets.
The malware is distributed through an affiliate-based criminal ecosystem in which operators maintain centralized infrastructure and management panels while affiliates run their own campaigns. Reporting has linked its development and lineage to Russian-speaking cybercriminal actors, including the developer identity Rodrigo4 in connection with Poseidon and earlier lineage. Odyssey has been especially active against macOS users in developer and cryptocurrency-adjacent contexts, but its victimology is broader and includes individual users, investors, and enterprise Mac environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Odyssey, in essence, is a sophisticated variation or updated iteration of the original Poseidon, designed to operate in the post-Gatekeeper bypass era.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The campaign reaches victims through deceptive software and update prompts, including ClickFix-style social-engineering lures that persuade users to run malicious commands.
In most scenarios, once users interact with the Fix or Verify button in the lure, the button will covertly copy an obfuscated PowerShell command to the clipboard and present the user with “verification steps.”
Once the fateful paste into a Terminal window took place, the traditional AppleScript stealer code we’ve observed in previous years executed to gather data and exfiltrate.
The main payload is obfuscated AppleScript wrapped in a shell script ... do shell script command_payload
The campaign reaches victims through deceptive software and update prompts, including ClickFix-style social-engineering lures that persuade users to run malicious commands.
adversaries created fake websites that mimic trusted macOS dev tools like Homebrew to spread Odyssey and Atomic Stealer.
All five clusters rely on a living-off-the-land (LotL) approach, using trusted system tools already present on the operating system to carry out the attack. By routing execution through native utilities like PowerShell or the macOS Terminal, attackers effectively operate outside the reach of most standard browser-based security defenses.
Odyssey Stealer brought with it a host of enhanced capabilities designed specifically to evade detection... These new features included: Anti-sandboxing mechanisms: Tools and logic to detect and avoid execution within analysis environments like virtual machines or emulators.
A fake dialog tricks the user into entering their macOS password ... The password is validated against the system using dscl . authonly
On macOS, this exact trap drops Odyssey Stealer to steal sensitive data.
Odyssey can take browser passwords and session cookies, which may allow an attacker to access an account without immediately knowing its password.
The researchers found that Odyssey can collect passwords, cookies, and autofill data from widely used browsers...
Odyssey Stealer brought with it a host of enhanced capabilities designed specifically to evade detection... These new features included: Anti-sandboxing mechanisms: Tools and logic to detect and avoid execution within analysis environments like virtual machines or emulators.
Once launched, the malware quietly searches the device for valuable information... By taking wallet data, cloud and developer credentials, messaging-app information, and local system records...
A fake dialog tricks the user into entering their macOS password ... The password is validated against the system using dscl . authonly
Botnet component: Adding functionality for persistent remote execution and control, indicating a move towards more complex capabilities beyond simple, one-time data exfiltration.
supporting arbitrary shell execution, reinfection, and a SOCKS5 proxy for tunneling traffic through victim machines ... enablesocks5 Downloads and runs SOCKS5 proxy
76 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS information-stealing malware that collects credentials, browser data, cryptocurrency wallet data, cloud and developer credentials, messaging-app information, SSH keys, shell history, and other sensitive files. It also establishes persistence via a LaunchDaemon, communicates with command-and-control infrastructure, and has been observed replacing wallet applications with trojanized versions to drain cryptocurrency wallets.
An infostealer delivered via fake ChatGPT desktop app download pages in the LLMShare campaign; it targets macOS users and steals sensitive data.
Information-stealing malware observed being downloaded by the spoofed Homebrew infrastructure as part of the campaign.
Information-stealing malware deployed via ClickFix campaigns, associated with credential theft and cryptocurrency wallet data harvesting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.