logo

‘Poseidon’ Mac stealer distributed via Google ads

ID: 97546963-198c-5637-ba25-8be2fca6ce9d

STIX ID: report--97546963-198c-5637-ba25-8be2fca6ce9d

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2024-06-27

Date Updated: 2026-04-28

...
...

Malwarebytes observed an active campaign distributing a macOS stealer called Poseidon (OSX.RodStealer) via malicious Google ads and fake Arc browser download pages; the stealer harvests browser data, crypto wallets, password managers and VPN configurations, and the report includes the DMG payload SHA256, malicious domains, and a C2 IP and panel screenshot.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.