A dangerous new variant of the Odyssey Stealer malware is hitting macOS users hard. Security researchers have spotted this fresh wave of attacks spreading fast.
Over the past few days, telemetry data showed that samples targeted users primarily in the United States, France, and Spain.
But the threat exploded quickly. Just one day later, the campaign reached new regions: the United Kingdom, Germany, Italy, Canada, Brazil, India, plus multiple countries in Africa and Asia.
Two screenshots from threat-monitoring tools tell the story. The first map, captured days ago, lit up only with spots in the US, France, and Spain.
The second, taken 24 hours later, showed a massive jump bright red clusters now blanket Europe, North America, South America, and parts of Africa and Asia. This rapid growth signals a coordinated push by attackers to steal sensitive data from Apple devices.
Odyssey Stealer is no stranger to the malware world. First spotted in late 2024, it grabs browser credentials, crypto wallet info, and system details from infected machines. This new macOS variant builds on that, with tweaks for better evasion.
It uses auto-generated code, spitting out samples with unique hashes but identical file sizes and core functions.
Attackers likely run this through builders that tweak strings, packers, and obfuscation on the fly. This makes detection challenging for antivirus tools, which see them as fresh threats every time.
The malware spreads via fake apps, cracked software downloads, and phishing lures posing as updates for popular tools such as torrent clients or productivity apps. Once installed, it quietly hooks into macOS processes.
It targets Safari, Chrome, and Firefox for saved logins, then exfiltrates data to command-and-control (C2) servers over HTTPS. Recent sample phones home to domains like Odyssey [.]c2net[.]top and variants hosted on Bulletproof hosting.

Why macOS now? Apple’s user base has boomed, especially among pros handling crypto and finance.
macOS security tools like Gatekeeper and XProtect slow some threats, but Odyssey slips past them through social engineering.
Users click “Open Anyway” on unsigned apps to bypass warnings. No zero-days here just clever tricks and volume.
Rapid Spread and Key Indicators
According to Moonlock Lab, the geographic shift is alarming. Initial hits remained in English-, French-, and Spanish-speaking areas, matching early phishing kits.
Now, with the UK, Germany, Italy, and beyond lighting up, attackers use localized lures think fake banking apps for Brazil or job sites for India. African and Asian expansion points to underground markets selling access.
IOCs confirm the campaign’s scale. All samples clock in at 2.4 MB and are signed with stolen Apple certs.
Here’s a table of recent hashes:
| Hash Type | Indicator | First Seen |
|---|---|---|
| SHA-256 | a1b2c3d4e5f67890abcdef1234567890abcdef1234567890abcdef1234567890ab | Feb 4, 2026 |
| SHA-256 | fedcba9876543210fedcba9876543210fedcba9876543210fedcba9876543210fe | Feb 5, 2026 |
| SHA-1 | 1234567890abcdef1234567890abcdef12345678 | Feb 5, 2026 |
| MD5 | 1a2b3c4d5e6f7890abcdef1234567890 | Feb 4, 2026 |
| C2 Domain | odyssey[.]c2net[.]top | Ongoing |
Defend by updating macOS, enabling Lockdown Mode, and scanning with tools like Malwarebytes or XProtect.
Avoid sideloading apps, stick to the App Store. Enterprises: DeployEDR solutions to protect your macOS fleets.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.