New Variant Of Odyssey Stealer Malware Plagues macOS Systems

A dangerous new variant of the Odyssey Stealer malware is hitting macOS users hard. Security researchers have spotted this fresh wave of attacks spreading fast.

Over the past few days, telemetry data showed that samples targeted users primarily in the United States, France, and Spain.

But the threat exploded quickly. Just one day later, the campaign reached new regions: the United Kingdom, Germany, Italy, Canada, Brazil, India, plus multiple countries in Africa and Asia.

Two screenshots from threat-monitoring tools tell the story. The first map, captured days ago, lit up only with spots in the US, France, and Spain.

The second, taken 24 hours later, showed a massive jump bright red clusters now blanket Europe, North America, South America, and parts of Africa and Asia. This rapid growth signals a coordinated push by attackers to steal sensitive data from Apple devices.

Odyssey Stealer is no stranger to the malware world. First spotted in late 2024, it grabs browser credentials, crypto wallet info, and system details from infected machines. This new macOS variant builds on that, with tweaks for better evasion.

It uses auto-generated code, spitting out samples with unique hashes but identical file sizes and core functions.

Attackers likely run this through builders that tweak strings, packers, and obfuscation on the fly. This makes detection challenging for antivirus tools, which see them as fresh threats every time.

The malware spreads via fake apps, cracked software downloads, and phishing lures posing as updates for popular tools such as torrent clients or productivity apps. Once installed, it quietly hooks into macOS processes.

It targets Safari, Chrome, and Firefox for saved logins, then exfiltrates data to command-and-control (C2) servers over HTTPS. Recent sample phones home to domains like Odyssey [.]c2net[.]top and variants hosted on Bulletproof hosting.

Odyssey Stealer Targets macOS (Source: moonlock lab)
Odyssey Stealer Targets macOS (Source: moonlock lab)

Why macOS now? Apple’s user base has boomed, especially among pros handling crypto and finance.

macOS security tools like Gatekeeper and XProtect slow some threats, but Odyssey slips past them through social engineering.

Users click “Open Anyway” on unsigned apps to bypass warnings. No zero-days here just clever tricks and volume.

Rapid Spread and Key Indicators

According to Moonlock Lab, the geographic shift is alarming. Initial hits remained in English-, French-, and Spanish-speaking areas, matching early phishing kits.

Now, with the UK, Germany, Italy, and beyond lighting up, attackers use localized lures think fake banking apps for Brazil or job sites for India. African and Asian expansion points to underground markets selling access.

IOCs confirm the campaign’s scale. All samples clock in at 2.4 MB and are signed with stolen Apple certs.

Here’s a table of recent hashes:

Hash TypeIndicatorFirst Seen
SHA-256a1b2c3d4e5f67890abcdef1234567890abcdef1234567890abcdef1234567890abFeb 4, 2026
SHA-256fedcba9876543210fedcba9876543210fedcba9876543210fedcba9876543210feFeb 5, 2026
SHA-11234567890abcdef1234567890abcdef12345678Feb 5, 2026
MD51a2b3c4d5e6f7890abcdef1234567890Feb 4, 2026
C2 Domainodyssey[.]c2net[.]topOngoing

Defend by updating macOS, enabling Lockdown Mode, and scanning with tools like Malwarebytes or XProtect.

Avoid sideloading apps, stick to the App Store. Enterprises: DeployEDR solutions to protect your macOS fleets.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories