Threat Actors Impersonate Microsoft Teams To Deliver Odyssey macOS Stealer Via Clickfix
ID: 38f7f72a-e950-502d-96e1-6dd6ff73aecb
STIX ID: report--38f7f72a-e950-502d-96e1-6dd6ff73aecb
Feed Name: CloudSEK Blog
CloudSEK (triaged with Forcepoint context) analyzed a clickfix campaign delivering the Odyssey AppleScript stealer to macOS users via impersonated download pages (TradingView/Microsoft Teams). The stealer runs under osascript, harvests keychains, browser data, Apple Notes, numerous desktop and extension crypto wallets, bundles data into /tmp/out.zip and exfiltrates it to a C2 (185.93.89.62/185.93.89.162 paths), establishes persistence via /Library/LaunchDaemons and replaces Ledger Live with a trojanized app; the report provides IOCs, mitigations, and a YARA rule.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
