Odyssey Stealer is an advanced malware-as-a-service (MaaS) offering that evolves from two well-known predecessor families: AMOS (Atomic macOS Stealer) and Poseidon Stealer. The threat actor behind this campaign is “Rodrigo” (alias Rodrigo4), a former AMOS developer who previously created Poseidon as an enhanced fork of AMOS before eventually selling that operation. With Odyssey, Rodrigo rebranded and significantly upgraded the Poseidon codebase to bypass modern macOS security defenses.
The campaign demonstrates a clear geographic preference for Western markets primarily the United States, European Union member states, and Canada while conspicuously avoiding victims in CIS (Commonwealth of Independent States) nations. This pattern is characteristic of Russian-aligned cybercriminal operations adhering to underground forum policies prohibiting malware targeting CIS countries. The majority of command-and-control (C2) infrastructure for Odyssey is hosted in Russia, further supporting this assessment.
Key Capabilities:
- Comprehensive cryptocurrency wallet theft (200+ browser extensions, 25+ desktop wallets)
- Advanced persistence via LaunchDaemons with stolen sudo credentials
- Trojanized Ledger Live application for supply chain compromise
- Botnet functionality enabling remote command execution
- SOCKS5 proxy deployment for pivoting through infected hosts









