New Wave of Odyssey Stealer Targets macOS Users in Active Cyberattack Campaign
ID: b6306a23-7cbc-53fd-aaab-7c0fb9e4df32
STIX ID: report--b6306a23-7cbc-53fd-aaab-7c0fb9e4df32
Feed Name: GBHackers
### Executive Summary The report documents a widespread surge of Odyssey Stealer targeting macOS users globally; the macOS infostealer—evolved from Poseidon/AMOS—uses fake CAPTCHA (ClickFix) social engineering, base64-decoded AppleScript installers, LaunchDaemon persistence, and exfiltration to attacker-controlled C2 servers (example IP: 45.46.130.131) to harvest browser credentials, macOS Keychain entries, cryptocurrency wallets, and files, with a builder and control panel enabling operator management and custom builds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
