216.73.217.22

Odyssey Stealer Malware Attacks macOS Users

· Published 07/08/2025 21:14 · Modified 07/08/2025 21:45

Export JSON

Essential information

Published
07/08/2025 21:14
Modified
07/08/2025 21:45
Tags
2025-08-07 applescript clickfix credential-theft crypto-wallet macos odyssey stealer phishing
Related entities
3 observables

Description

A campaign targeting users employs a technique to deliver the malware. The attack uses a fake CAPTCHA verification page that executes without dropping a binary on the system. When users follow the instructions, they unknowingly execute a malicious that collects sensitive data, including crypto wallet information, browser extensions, cookies, saved keychains, usernames, and passwords. The script creates a ZIP archive of the stolen data and exfiltrates it to a command and control server. This sophisticated attack blends and social engineering to bypass traditional detection methods, making it challenging to detect and analyze.

External references