Odyssey Stealer: Inside a macOS Crypto-Stealing Operation
ID: 36dd3b59-afac-5ee9-83d4-5a2d18dadb99
STIX ID: report--36dd3b59-afac-5ee9-83d4-5a2d18dadb99
Feed Name: Censys Blog
Date Published: 2026-02-11
Date Updated: 2026-04-27
Author: Ivonne Francia; Aidan Holland; Senior Security Researcher
Odyssey Stealer is a macOS-focused information stealer sold as a MaaS targeting cryptocurrency users: it harvests browser and desktop wallet data, steals macOS credentials and Keychain items, replaces Ledger/Trezor apps with trojanized loaders, and maintains persistence via a LaunchDaemon with a RAT loop and SOCKS5 proxy. The report provides a full technical analysis of payload stages, C2/API endpoints, infrastructure fingerprinting (Censys body/favicon/asset hashes), affiliate build identifiers, numerous IOCs (IPs, domains, file and executable hashes), lineage to Poseidon/AMOS, attribution hints, and actionable detection/mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
