Cybercriminals targeted macOS users in German-speaking Switzerland with phishing emails impersonating AGOV, the Swiss government login service, to deliver the Poseidon Stealer malware. Swiss authorities said the messages claimed AGOV access would become mandatory for public online services and were sent through Amazon's legitimate outbound email infrastructure, increasing their credibility. Recipients were directed through a bing.com link and then redirected via a likely compromised website to attacker-controlled domains hosting a malicious disk image, AGOV-Access.dmg.
Once installed, Poseidon Stealer harvested sensitive data from infected Macs, including login credentials, browser cookies, private keys, and cryptocurrency wallet information. The malware compressed the stolen data into a ZIP archive and exfiltrated it to command-and-control infrastructure, including the endpoint at 79.137.192.4/p2p. Swiss analysis found the malware remained on the device after a restart but was no longer executed, indicating the campaign prioritized rapid credential and wallet theft over long-term persistence.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
On July 11, 2024, the Swiss NCSC published a brief technical analysis of the Poseidon Stealer malware used in the AGOV-themed phishing campaign. The analysis described the malware's data theft and exfiltration behavior and noted it remains on infected devices after restart but no longer executes.
The Swiss NCSC referenced a notification dated June 28, 2024 about malware for macOS being spread through emails purportedly from AGOV. This reflects the agency's public warning following reports about the phishing campaign.
On the evening of June 27, 2024, Switzerland's NCSC observed a large malspam campaign targeting macOS users in Switzerland. The phishing emails impersonated AGOV and lured recipients to download a malicious DMG file that installed Poseidon Stealer.
At the end of June 2024, cybercriminals distributed Poseidon Stealer by email in German-speaking Switzerland, again impersonating the Swiss government login service AGOV. The campaign targeted macOS systems and sought credentials, cookies, private keys, and cryptocurrency wallet data for exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.