logo

Odyssey Stealer: Inside a macOS Crypto-Stealing Operation

ID: 36dd3b59-afac-5ee9-83d4-5a2d18dadb99

STIX ID: report--36dd3b59-afac-5ee9-83d4-5a2d18dadb99

Feed Name: Censys Blog

Threat Score
78/100

Date Published: 2026-02-11

Date Updated: 2026-04-27

Author: Ivonne Francia; Aidan Holland; Senior Security Researcher

...
...

Odyssey Stealer is a macOS-focused information stealer sold as a MaaS targeting cryptocurrency users: it harvests browser and desktop wallet data, steals macOS credentials and Keychain items, replaces Ledger/Trezor apps with trojanized loaders, and maintains persistence via a LaunchDaemon with a RAT loop and SOCKS5 proxy. The report provides a full technical analysis of payload stages, C2/API endpoints, infrastructure fingerprinting (Censys body/favicon/asset hashes), affiliate build identifiers, numerous IOCs (IPs, domains, file and executable hashes), lineage to Poseidon/AMOS, attribution hints, and actionable detection/mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.