Search the site
Press ESC to close
LIVE
Loading...
Updating...

Odyssey Infostealer Targets macOS: Crypto Wallets Under Threat

Wei Liang Mo
Fact-checked
2 min read
369 words
Share

Security researchers at Moonlock Lab have identified a significant surge in the activity of the Odyssey infostealer, a sophisticated Trojan specifically targeting macOS users. The malware has already impacted systems across more than 100 countries, demonstrating a global reach and a high level of technical coordination. This threat is designed to exfiltrate sensitive system information and private data, with a primary focus on draining digital asset holdings from both software and hardware wallet interfaces.

Extensive Data Theft and System Persistence

The Odyssey Trojan employs a multi-faceted approach to data extraction, targeting a wide range of browser and system information. It is capable of harvesting passwords, cookies, and autofill data from major browsers, including Chrome, Brave, and Edge. Beyond browser data, the malware accesses SSH keys, cloud service configurations, and the macOS Keychain database. The Keychain is a centralized repository in macOS used to store passwords and account information, making its compromise particularly dangerous for users.

Furthermore, the Trojan ensures its longevity on infected devices by installing a background service that triggers automatically upon system boot. It also monitors communication platforms, specifically targeting data from Telegram and Discord, which are frequently used by cryptocurrency communities for project updates and peer-to-peer networking.

Targeting Cryptocurrency Wallets and Browser Extensions

A core component of the Odyssey attack involves the systematic theft of cryptocurrency-related assets. The malware targets more than 16 dedicated applications and approximately 300 browser extension IDs associated with digital assets. Notable targets include:

  • Popular software wallets such as Electrum and Exodus.
  • Desktop interfaces for hardware wallets like Ledger Live.
  • Trojanized versions of Ledger, Trezor, and Exodus applications.

In a particularly aggressive tactic, the malware replaces legitimate wallet applications with Trojanized versions capable of intercepting keys and diverting funds directly to the attackers. Security analysts have publicly disclosed the Command and Control (C2) server addresses used by the malware to help network administrators block malicious traffic.

To mitigate the risk of infection, macOS users are advised to verify the integrity of their wallet software and utilize hardware-based signing for all transactions. As the Odyssey infostealer continues to evolve, maintaining updated security software and avoiding unofficial software downloads remains critical for protecting digital wealth in the decentralized ecosystem.

Frequently Asked Questions

Quick answers to the most common questions about this topic.