logo

Odyssey Stealer & AMOS Hit macOS Developers with Fake Homebrew Sites

ID: 5ba12f64-c522-5c27-8175-fff52105fb4d

STIX ID: report--5ba12f64-c522-5c27-8175-fff52105fb4d

Feed Name: Hunt.io Blog

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report documents an active, coordinated campaign targeting macOS developers using fake download portals and clipboard-based social engineering to trick victims into pasting base64-encoded curl commands that install Odyssey Stealer or AMOS; investigators identified 85+ phishing domains, reused SSL certificates and multi-year infrastructure (notably IPs 93.152.230.79 and 195.82.147.38), analyzed payload behavior (privilege escalation attempts, anti-analysis, service manipulation, and credential/crypto theft), and provided IOCs and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.