logo

New Wave of Odyssey Stealer Targets macOS Users in Active Cyberattack Campaign

ID: b6306a23-7cbc-53fd-aaab-7c0fb9e4df32

STIX ID: report--b6306a23-7cbc-53fd-aaab-7c0fb9e4df32

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-02-06

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

### Executive Summary The report documents a widespread surge of Odyssey Stealer targeting macOS users globally; the macOS infostealer—evolved from Poseidon/AMOS—uses fake CAPTCHA (ClickFix) social engineering, base64-decoded AppleScript installers, LaunchDaemon persistence, and exfiltration to attacker-controlled C2 servers (example IP: 45.46.130.131) to harvest browser credentials, macOS Keychain entries, cryptocurrency wallets, and files, with a builder and control panel enabling operator management and custom builds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.