Poseidon Stealer
Aliases: Rodrigo Stealer
- First seen
- 2023-05-01 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:38:26
- Profile updated
- 2026-07-07 14:35:13
Targeted industries: technology-and-telecommunications
Context
macOS infostealer sold by an individual named Rodrigo4, currently consisting of a disk image containing a Mach-O without app bundle, which when executed spawns osascript executing an AppleScript with the actual infostealer payload. The AppleScript payload will steal files by packing them in a ZIP archive and uploading them to a hardcoded C2 via HTTP.
Reports & references
- redcanary.com — Atomic Odyssey Poseidon Stealers (report)
- malpedia.caad.fkie.fraunhofer.de — Osx.Poseidonstealer (report)
- malwarebytes.com — Poseidon Mac Stealer Distributed Via Google Ads (report)
- ncsc.admin.ch — Poseidon Bericht (report)
- github.com — 20240627 Macos Poseidonstealer (report)