Global Surge of 'Odyssey' Trojan Puts macOS Users and Crypto Assets at Risk
A sophisticated information-stealing Trojan targeting macOS has seen a significant spike in activity, according to recent cybersecurity monitoring. Dubbed 'Odyssey,' this malware variant has already impacted users in more than 100 countries worldwide, marking a concerning escalation in threats against the Apple ecosystem.
Multi-Faceted Data Theft: From Browsers to Crypto Wallets
The 'Odyssey' Trojan distinguishes itself with a broad and modular set of data-harvesting capabilities, compromising multiple aspects of a user's digital presence.
- Comprehensive Browser Compromise: The malware systematically steals saved passwords, cookies, and autofill data from major browsers including Chrome, Brave, and Edge. This grants attackers potential access to a wide array of online accounts.
- Cryptocurrency Assets in the Crosshairs: It specifically targets digital currency holders by exfiltrating data files from over 16 popular cryptocurrency wallet applications. It also scans for and logs the IDs of approximately 300 crypto-related browser extensions.
- System and Communication Privacy Breached: The Trojan's reach extends deep into system privacy. It is capable of stealing SSH keys, cloud service configuration files, the macOS Keychain database, and local data from messaging apps like Telegram and Discord.
Persistent Threat: Backdoor Installation and Application Hijacking
The threat posed by 'Odyssey' is not limited to a one-time data grab. To ensure persistence and control, it employs advanced techniques:
Firstly, it installs a background service configured to launch automatically at startup, maintaining a foothold on the infected machine even after reboots. Secondly, in a more direct attempt to hijack assets, it performs a dangerous "binary swap"—replacing legitimate hardware wallet management and desktop wallet applications with trojanized versions that look identical but are designed to siphon funds. Transactions made through these compromised apps can lead to irreversible asset loss.
Security researchers have now publicly disclosed indicators of compromise, including command-and-control server addresses associated with this campaign. macOS users are urged to ensure their systems and security software are updated, download applications only from official or trusted sources, and remain vigilant for any unusual network or application behavior.