Poseidon is a Go-based post-exploitation agent for the open-source Mythic command-and-control framework, primarily used against macOS and also available for Linux. It supports host profiling and remote tasking including shell execution, process and directory enumeration, file upload and download, screen capture, keylogging, clipboard monitoring, SSH credential testing, port scanning, SOCKS proxying, and persistence-related actions. macOS variants support persistence through LaunchAgents, LaunchDaemons, and Login Items. Poseidon has been deployed in the CrateDepression Rust supply-chain campaign against GitLab CI environments and in phishing campaigns targeting Indian government personnel using UNIX-based systems; APT36/Transparent Tribe has used Poseidon, though the publicly available agent alone is not sufficient for attribution. The name Poseidon is also used for unrelated macOS infostealer and point-of-sale RAM-scraping malware families, which should not be conflated with the Mythic agent.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Помимо Crimson RAT, в арсенал APT36 входят DeskRAT, AresRAT, AllaKore, GetaRAT и Poseidon.
The threat actor rebranded the new project ‘Poseidon’ and added a few new features such as looting VPN configurations.
We observed that Mythic Agents had been utilized by the APT-36 group in their operations. One such Agent is “Poseidon.”
this report explains the usage of Poseidon malware which targets government employees who use UNIX-based systems for their jobs ... The 2nd stage file is defined as a payload named Poseidon, written in Go programming language and included in the MythicAgents project on GitHub.
After gaining initial access to the developer's machine, attackers deployed MythicC2's Poseidon agent, a robust Golang-based payload offering advanced stealth and extensive post-exploitation capabilities for macOS environments.
38 distinct techniques documented for this family, organized by ATT&CK tactic.
People who clicked on the ad were redirected to arc-download[.]com, a completely fake site offering Arc for Mac only.
attackers need to take advantage of techniques more similar to those we see in Windows systems, such as Cron Jobs
The first ELF file detected in the attack campaign is the Python script file wrapped in ELF format... By extracting the compiled Python file (Kavach.pyc)... it becomes clear to understand the purpose of the 1st stage file.
attackers need to take advantage of techniques more similar to those we see in Windows systems, such as Cron Jobs
case 42 : //Execute persist_launch command to install launchd //persistence go persist_launchd.Run ( task )
attackers need to take advantage of techniques more similar to those we see in Windows systems, such as Cron Jobs
An embedded PE is extracted through shellcode and execution continues with the embedded binary.
case 42 : //Execute persist_launch command to install launchd //persistence go persist_launchd.Run ( task )
На практике для обхода XProtect хватает двух: шифрование строк (характерные user-agent, URL-паттерны) и пересборка из исходников с рефакторингом структуры бинаря
The downloaded DMG file resembles what one would expect when installing a new Mac application with the exception of the right-click to open trick to bypass security protections.
There is a new malware family targeting PoS systems, infecting machines to scrape memory for credit card information and exfiltrate that data to servers.
The downloaded binary, FindStr, installs a keylogger and scans the memory of the PoS device for number sequences that could be credit card numbers.
case 17 : // Test credentials against remote hosts go sshauth.Run ( task )
The script copied and exfiltrated a number of items, among which were any SSH keys located on the victims’ device.
The stealer offers functionalities reminescent of Atomic Stealer including: file grabber, crypto wallet extractor, password manager (Bitwarden, KeePassXC) stealer, and browser data collector.
case 25 : // Retrieve information about the current user. go getuser.Run ( task )
case 18 : // Scan ports on remote hosts. go portscan.Run ( task )
The PE then cycles through all running processes on the PoS device to look for processes with a security token not associated with the “NT AUTHORITY” domain name.
The stealer offers functionalities reminescent of Atomic Stealer including: file grabber, crypto wallet extractor, password manager (Bitwarden, KeePassXC) stealer, and browser data collector.
There is a new malware family targeting PoS systems, infecting machines to scrape memory for credit card information and exfiltrate that data to servers.
Credit card numbers and keylogger data is sent to the exfiltration server after being XORed and base64 encoded.
168 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Вредоносный инструмент, названный частью ротируемого инструментария APT36; назначение в материале не уточняется.
Named as a RAT among the malware/tools detected in the incident context.
Referenced as an example of existing macOS malware in background context only.
C2 agent referenced as an example of an already-deployed implant on a target macOS host.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.