TF-MAL-osx.odyssey_stealer
📛 Threat Title
Malware family: Odyssey Stealer
Description
ThreatFox malware family `osx.odyssey_stealer`. Printable name: Odyssey Stealer.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as OdysseyStealer .
-
web:blog.netmanageit.com
A new variant of the Odyssey infostealer for macOS has been discovered, featuring code signing, notarization, and a persistent backdoor. The malware mimics a Google Meet updater and uses a SwiftUI-based 'Technician Panel' for social engineering. It steals sensitive data, including passwords, browser information, and cryptocurrency wallet contents.
-
web:gist.github.com
The malware is an instance of Odyssey Stealer (a rebrand of Poseidon Stealer , itself a fork of AMOS/Atomic Stealer ) -- a sophisticated macOS credential and cryptocurrency theft tool distributed as Malware -as-a-Service (MaaS) by a Russian-speaking threat actor known as "Rodrigo."
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Odyssey Stealer malware family including references, samples and yara signatures.
-
web:redcanary.com
The core challenge for defenders has become finding subtle, yet reliable, indicators that can precisely attribute a stealer to a specific family . Such granular attribution is vital for informing threat intelligence, understanding adversary tactics, and ultimately enabling more precise detection and mitigation strategies.
-
web:socprime.com
Summary Odyssey Stealer is a macOS infostealer focused on cryptocurrency wallets and extensions. It's marketed as a Malware -as-a-Service platform where affiliates rent access to a centralized C2 and admin panel. Delivery typically relies on obfuscated AppleScript that installs a persistent LaunchDaemon which polls the C2 for commands.
-
web:www.cyfirma.com
Other Settings Controls panel behaviour We found multiple Odyssey Stealer Panels mostly hosted in Russia. EXTERNAL THREAT LANDSCAPE MANAGEMENT Odyssey Stealer represents the latest evolution in macOS-targeting malware , emerging as a rebranded version of Poseidon Stealer which itself originated as a fork of the AMOS Stealer .
-
web:www.forcepoint.com
The Odyssey Stealer comes in the form of a phishing campaign that targets macOS via a ClickFix technique that delivers malware designed to steal credentials.
-
web:www.jamf.com
Discover new technical insights into the Odyssey Stealer malware , including signed & notarized variants, SwiftUI-based social engineering, and advanced persistence techniques.
-
web:www.pcrisk.com
What kind of malware is Odyssey ? Odyssey is a variant of AMOS (Atomic) stealer malware targeting macOS users. It is designed to pilfer sensitive information from infected devices, including files, app data, and cryptocurrency wallets. Victims of this stealer can suffer monetary loss, become victims of identity theft, and encounter other issues.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.