s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.poseidonstealer

📛 Threat Title

Malware family: Poseidon Stealer

Category: Poseidon Stealer First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.poseidonstealer`. Printable name: Poseidon Stealer. Aliases: Rodrigo Stealer.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.poseidonstealer VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.poseidonstealer

IOC database

Type
domain
Value
osx.poseidonstealer
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.poseidonstealer

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.poseidonstealer

References (1)

Remediations (10)

  • web:aviatrix.ai

    Attack Path Analysis The attack began with the delivery and execution of a macOS stealer such as Atomic, Poseidon , or Odyssey via phishing or drive-by download. Upon installation, the malware leveraged access to steal sensitive data and credentials, possibly attempting to escalate privileges depending on security context.

  • web:cybernews.com

    A rebranded malvertising campaign - dubbed " Poseidon " by its creator - has been actively targeting Mac users via malicious Google Ads in an attempt to steal users' personal information, a new Malwarebytes Lab report found. The data stealing malware is being distributed through fake Google Ads advertising downloads for the relatively new Arc browser, the researchers warn. The macOS ...

  • web:cybersecuritynews.com

    Anti-Analysis and Evasion Techniques Poseidon Stealer implements layered anti-debugging measures, a secondary check uses sysctl to inspect the P_TRACED flag in process status. Anti-debug via ptrace () The malware terminates if usernames match common researcher aliases like "maria" or "jackiemac" through AppleScript validation.

  • web:redcanary.com

    While distinguishing between stealer families with detail is crucial for threat intelligence, tracking, and proactive defense, the immediate remediation steps for compromised macOS systems largely remains consistent regardless of the specific stealer identified.

  • web:techowlshield.com

    Technical Analysis Poseidon hides itself inside a fake macOS app. It usually comes in a DMG file that looks like a trusted application 'MacAppsLauncher'. When the user opens the DMG file, it extracts a Mach-O file. This file looks like it is part of a normal system update, but in reality, it is the main stealer malware . Once opened, it starts collecting important data from the system like ...

  • web:www.cyfirma.com

    The malware operators employ "ClickFix" distribution tactics, luring victims through fake macOS App Store websites. Current evidence indicates that while Odyssey/ Poseidon and AMOS share common ancestry, they are being developed as competing products in the growing macOS malware -as-a-service ecosystem.

  • web:www.malwarebytes.com

    Info stealers are a type of malware that resides in an infected computer and gathers data in order to send it to the attacker. Protection Malwarebytes for Mac detects and removes OSX. Poseidon . Remediation Malwarebytes for Mac will detect and remove the components of this malware . Download and install the latest version of Malwarebytes for Mac.

  • web:www.ncsc.admin.ch

    The malicious emails asked the recipients to download a software package for macOS, which in fact was a malware called " Poseidon Stealer ". The brief technical analysis by NCSC shows how " Poseidon Stealer " works in order to access and steal the victims' data.

  • web:www.pcrisk.com

    What kind of malware is Poseidon ? Poseidon is a stealer -type malware targeting macOS devices. This malicious program seeks to acquire files, log-in credentials, cryptowallets, and other sensitive information. In the early summer of 2024, Poseidon was observed proliferating via malicious Google ads. Poseidon malware overview As mentioned in the introduction, Poseidon is designed to extract and ...

  • web:www.sentinelone.com

    Poseidon and Amos | Summer Stealers 2024 If the drama being played out in crimeware forums and Telegram discussion groups is to be believed, Poseidon is the main rival to the original Amos Atomic family and is widely attributed to a threat actor alias 'Rodrigo'.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.