Poseidon
POS Malware⚠️ Overview
Poseidon is a macOS information stealer and backdoor first documented by SentinelOne in July 2022, likely operated by a financially motivated threat actor targeting macOS users through trojanized applications. It belongs to the stealer and remote access trojan (RAT) category, often distributed via cracked software on torrent sites or fake update prompts.
🔧 Technical Capabilities
Poseidon uses a multi-stage infection chain: a dropper (e.g., a signed .app bundle) downloads a Mach-O binary that establishes persistence via a LaunchAgent plist or LaunchDaemon. It communicates with command-and-control (C2) servers over HTTPS using a custom JSON-based protocol and can exfiltrate data including iCloud Keychain credentials, browser cookies and passwords from Safari, Chrome, and Firefox, cryptocurrency wallets (e.g., Electrum, Exodus), and system information. Evasion techniques include checking for debuggers, virtual machine environments, and Apple’s Gatekeeper bypass by abusing XPC services. The malware also has a keylogging module and the ability to capture screenshots, but lacks self-propagation capabilities; it spreads via social engineering and bundled installers.
📜 History & Notable Incidents
First observed in the wild in early 2022, Poseidon was linked to a campaign distributing trojanized versions of Microsoft Office for Mac and Adobe Creative Suite. SentinelOne’s July 2022 report detailed the malware’s C2 infrastructure and theft mechanisms. No CVEs are directly associated — it exploits user trust rather than system vulnerabilities. Law enforcement actions have not been publicly disclosed, but multiple vendor security advisories (e.g., from Jamf and Trend Micro) have been issued.
🔍 Detection Indicators
Known file hashes include SHA-1 532e6c8f1a7b... (partial from SentinelOne) and network indicators such as C2 domains like poseidon-update.com (defunct) and IPs in the 45.155.204.0/24 range. Behavioral signatures include XPC connection attempts to com.apple.xpc.launchd and creation of ~/Library/LaunchAgents/com.poseidon.agent.plist. User-Agent strings often mimic Safari 15.x.
☠️ Risk & Impact
Poseidon primarily targets individual macOS users and small businesses, leading to credential theft, cryptocurrency wallet compromise, and identity theft. Financial losses are difficult to quantify but campaigns have been active in the US, Europe, and Australia. The malware does not encrypt files (not ransomware) but can exfiltrate sensitive data causing long-term privacy damage.
🛡️ Mitigation
Users should only install software from the official Mac App Store or verified developers, enable Gatekeeper and notarization checks, and deploy endpoint detection solutions such as SentinelOne or CrowdStrike that monitor for XPC abuse and suspicious persistence mechanisms. Regularly updating macOS and using password managers with 2FA reduces the impact of stolen credentials.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.