Poseidon Stealer

Aliases: Rodrigo Stealer

First seen
2023-05-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Last IoC activity
2026-07-22 00:38:26
Profile updated
2026-07-07 14:35:13

Targeted industries: technology-and-telecommunications

Context

macOS infostealer sold by an individual named Rodrigo4, currently consisting of a disk image containing a Mach-O without app bundle, which when executed spawns osascript executing an AppleScript with the actual infostealer payload. The AppleScript payload will steal files by packing them in a ZIP archive and uploading them to a hardcoded C2 via HTTP.

Reports & references

  • redcanary.com — Atomic Odyssey Poseidon Stealers (report)
  • malpedia.caad.fkie.fraunhofer.de — Osx.Poseidonstealer (report)
  • malwarebytes.com — Poseidon Mac Stealer Distributed Via Google Ads (report)
  • ncsc.admin.ch — Poseidon Bericht (report)
  • github.com — 20240627 Macos Poseidonstealer (report)

External references