TF-MAL-osx.poseidonstealer
📛 Threat Title
Malware family: Poseidon Stealer
Description
ThreatFox malware family `osx.poseidonstealer`. Printable name: Poseidon Stealer. Aliases: Rodrigo Stealer.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.poseidonstealer
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.poseidonstealer
IOC database
- Type
- domain
- Value
osx.poseidonstealer- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.poseidonstealer
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.poseidonstealer
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:aviatrix.ai
Attack Path Analysis The attack began with the delivery and execution of a macOS stealer such as Atomic, Poseidon , or Odyssey via phishing or drive-by download. Upon installation, the malware leveraged access to steal sensitive data and credentials, possibly attempting to escalate privileges depending on security context.
-
web:cybernews.com
A rebranded malvertising campaign - dubbed " Poseidon " by its creator - has been actively targeting Mac users via malicious Google Ads in an attempt to steal users' personal information, a new Malwarebytes Lab report found. The data stealing malware is being distributed through fake Google Ads advertising downloads for the relatively new Arc browser, the researchers warn. The macOS ...
-
web:cybersecuritynews.com
Anti-Analysis and Evasion Techniques Poseidon Stealer implements layered anti-debugging measures, a secondary check uses sysctl to inspect the P_TRACED flag in process status. Anti-debug via ptrace () The malware terminates if usernames match common researcher aliases like "maria" or "jackiemac" through AppleScript validation.
-
web:redcanary.com
While distinguishing between stealer families with detail is crucial for threat intelligence, tracking, and proactive defense, the immediate remediation steps for compromised macOS systems largely remains consistent regardless of the specific stealer identified.
-
web:techowlshield.com
Technical Analysis Poseidon hides itself inside a fake macOS app. It usually comes in a DMG file that looks like a trusted application 'MacAppsLauncher'. When the user opens the DMG file, it extracts a Mach-O file. This file looks like it is part of a normal system update, but in reality, it is the main stealer malware . Once opened, it starts collecting important data from the system like ...
-
web:www.cyfirma.com
The malware operators employ "ClickFix" distribution tactics, luring victims through fake macOS App Store websites. Current evidence indicates that while Odyssey/ Poseidon and AMOS share common ancestry, they are being developed as competing products in the growing macOS malware -as-a-service ecosystem.
-
web:www.malwarebytes.com
Info stealers are a type of malware that resides in an infected computer and gathers data in order to send it to the attacker. Protection Malwarebytes for Mac detects and removes OSX. Poseidon . Remediation Malwarebytes for Mac will detect and remove the components of this malware . Download and install the latest version of Malwarebytes for Mac.
-
web:www.ncsc.admin.ch
The malicious emails asked the recipients to download a software package for macOS, which in fact was a malware called " Poseidon Stealer ". The brief technical analysis by NCSC shows how " Poseidon Stealer " works in order to access and steal the victims' data.
-
web:www.pcrisk.com
What kind of malware is Poseidon ? Poseidon is a stealer -type malware targeting macOS devices. This malicious program seeks to acquire files, log-in credentials, cryptowallets, and other sensitive information. In the early summer of 2024, Poseidon was observed proliferating via malicious Google ads. Poseidon malware overview As mentioned in the introduction, Poseidon is designed to extract and ...
-
web:www.sentinelone.com
Poseidon and Amos | Summer Stealers 2024 If the drama being played out in crimeware forums and Telegram discussion groups is to be believed, Poseidon is the main rival to the original Amos Atomic family and is widely attributed to a threat actor alias 'Rodrigo'.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.