Poseidon
Poseidon is a cybercrime threat actor/group associated in the provided content with Poseidon Stealer activity and described in one source as a Portuguese-speaking cybercrime group. The content also states that Poseidon Stealer was forked from Atomic macOS Stealer (AMOS) and later directly rebranded as Odyssey Stealer. Reported lineage in the content ties Poseidon and Odyssey to a developer known as Rodrigo4 on the Russian-language XSS forum, with Poseidon launched in mid-2024, sold in August 2024, and subsequently rebranded to Odyssey by new operators in mid-2025. The malware associated with this ecosystem is macOS-focused and aimed primarily at cryptocurrency theft, operating as a Malware-as-a-Service platform with an affiliate model. Described capabilities include delivery via obfuscated AppleScript payloads; theft of browser, wallet, Keychain, Telegram Desktop, Apple Notes, Desktop, and Documents data; targeting of numerous browser wallet extensions and desktop wallet applications; fake macOS password prompts validated with dscl . authonly; replacement of legitimate Ledger and Trezor applications with trojanized versions; installation of persistent LaunchDaemons; RAT functionality including arbitrary shell execution, reinfection, SOCKS5 proxying, and periodic polling of C2 infrastructure. The content also notes that after compromising a victim, Poseidon Group lists all running processes. Known related names and aliases directly mentioned in the content are Poseidon, Poseidon Stealer, and Odyssey Stealer.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Financial Services
Where they're from
Attributed origin per open-source reporting.
- RU
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a prior activity cluster associated with infrastructure (IP 91.92.242[.]30) that is also observed in the ClawHavoc campaign; no additional Poseidon-specific operations are detailed in this content beyond the infrastructure linkage.
Earlier macOS stealer MaaS platform that was rebranded into Odyssey; described as a competing product launched by Rodrigo4 after leaving AMOS.
Performs post-compromise host reconnaissance by enumerating running processes.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.