logo

Threat Actors Impersonate Microsoft Teams To Deliver Odyssey macOS Stealer Via Clickfix

ID: 38f7f72a-e950-502d-96e1-6dd6ff73aecb

STIX ID: report--38f7f72a-e950-502d-96e1-6dd6ff73aecb

Feed Name: CloudSEK Blog

Threat Score
75/100

Date Published: 2025-09-05

Date Updated: 2026-04-27

...
...

CloudSEK (triaged with Forcepoint context) analyzed a clickfix campaign delivering the Odyssey AppleScript stealer to macOS users via impersonated download pages (TradingView/Microsoft Teams). The stealer runs under osascript, harvests keychains, browser data, Apple Notes, numerous desktop and extension crypto wallets, bundles data into /tmp/out.zip and exfiltrates it to a C2 (185.93.89.62/185.93.89.162 paths), establishes persistence via /Library/LaunchDaemons and replaces Ledger Live with a trojanized app; the report provides IOCs, mitigations, and a YARA rule.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.