s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.odyssey_stealer

📛 Threat Title

Malware family: Odyssey Stealer

Category: Odyssey Stealer First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.odyssey_stealer`. Printable name: Odyssey Stealer.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as OdysseyStealer .

  • web:blog.netmanageit.com

    A new variant of the Odyssey infostealer for macOS has been discovered, featuring code signing, notarization, and a persistent backdoor. The malware mimics a Google Meet updater and uses a SwiftUI-based 'Technician Panel' for social engineering. It steals sensitive data, including passwords, browser information, and cryptocurrency wallet contents.

  • web:gist.github.com

    The malware is an instance of Odyssey Stealer (a rebrand of Poseidon Stealer , itself a fork of AMOS/Atomic Stealer ) -- a sophisticated macOS credential and cryptocurrency theft tool distributed as Malware -as-a-Service (MaaS) by a Russian-speaking threat actor known as "Rodrigo."

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Odyssey Stealer malware family including references, samples and yara signatures.

  • web:redcanary.com

    The core challenge for defenders has become finding subtle, yet reliable, indicators that can precisely attribute a stealer to a specific family . Such granular attribution is vital for informing threat intelligence, understanding adversary tactics, and ultimately enabling more precise detection and mitigation strategies.

  • web:socprime.com

    Summary Odyssey Stealer is a macOS infostealer focused on cryptocurrency wallets and extensions. It's marketed as a Malware -as-a-Service platform where affiliates rent access to a centralized C2 and admin panel. Delivery typically relies on obfuscated AppleScript that installs a persistent LaunchDaemon which polls the C2 for commands.

  • web:www.cyfirma.com

    Other Settings Controls panel behaviour We found multiple Odyssey Stealer Panels mostly hosted in Russia. EXTERNAL THREAT LANDSCAPE MANAGEMENT Odyssey Stealer represents the latest evolution in macOS-targeting malware , emerging as a rebranded version of Poseidon Stealer which itself originated as a fork of the AMOS Stealer .

  • web:www.forcepoint.com

    The Odyssey Stealer comes in the form of a phishing campaign that targets macOS via a ClickFix technique that delivers malware designed to steal credentials.

  • web:www.jamf.com

    Discover new technical insights into the Odyssey Stealer malware , including signed & notarized variants, SwiftUI-based social engineering, and advanced persistence techniques.

  • web:www.pcrisk.com

    What kind of malware is Odyssey ? Odyssey is a variant of AMOS (Atomic) stealer malware targeting macOS users. It is designed to pilfer sensitive information from infected devices, including files, app data, and cryptocurrency wallets. Victims of this stealer can suffer monetary loss, become victims of identity theft, and encounter other issues.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.