Last seven days
- First activity
- Jul 20, 2026
- Last activity
- Jul 20, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 1 hostnames
Poseidon is a name used for multiple distinct malware strains, most prominently a macOS-focused infostealer and a Go-based Mythic post-exploitation agent/backdoor for macOS and Linux.
Profile source: Mallory opens in a new tabPoseidon
Poseidon is a name used for multiple distinct malware strains, most prominently a macOS-focused infostealer and a Go-based Mythic post-exploitation agent/backdoor for macOS and Linux. The macOS infostealer variant is widely recognized as a fork of Atomic macOS Stealer (AMOS) and became one of the most active Mac stealers in late 2024. It targets browser credentials and cookies, password manager data, cryptocurrency wallets, VPN configurations, and other user secrets, and has been associated with malvertising, fake software installers, cracked-software lures, and social-engineering prompts that mimic native Apple dialogs to harvest credentials. Reported capabilities include theft of browser passwords and cookies, cryptocurrency wallet data, and other application secrets from both consumer and business Mac systems.
Separately, Poseidon is also the primary macOS agent for the Mythic C2 framework, written in Go and used as a full-featured post-exploitation backdoor. This Poseidon agent has been observed in supply-chain compromises and targeted intrusions, including deployment on macOS and Linux systems after initial access. Reported functionality includes beaconing, shell execution, file operations, process listing, screenshot capture, clipboard monitoring, keylogging, credential harvesting, persistence, and support for lateral movement. On macOS, persistence mechanisms have included LaunchAgent, LaunchDaemon, and Login Item techniques. The Mythic Poseidon agent has been referenced in operations involving developer and CI/CD environments, as well as activity attributed to Transparent Tribe/APT36 and other intrusion sets using Linux-oriented RAT workflows.
Because the same name is used for both an infostealer lineage and a Mythic backdoor agent, attribution and classification should be handled carefully in operational contexts. In current security reporting, the most commonly searched and recognized use of Poseidon in the macOS malware ecosystem is the AMOS-derived infostealer.
Samples
Reported operators
After gaining initial access to the developer's machine, attackers deployed MythicC2's Poseidon agent, a robust Golang-based payload offering advanced stealth and extensive post-exploitation capabilities for macOS environments.
Tied together with six months of passive DNS, this is the fourth Linux-oriented RAT family APT36 has rotated through since mid-2024 (Poseidon β AresRAT β DeskRAT, alongside the parallel Windows CrimsonRAT track).
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.