A sophisticated cyber campaign is targeting macOS users by distributing the potent “Odyssey” information stealer through a deceptive website impersonating the official Microsoft Teams download page.
The attack, identified by researchers at CloudSEK’s TRIAD, leverages a social engineering technique known as a “Clickfix” attack to trick victims into executing malicious code that systematically harvests sensitive data, establishes long-term persistence, and even replaces legitimate cryptocurrency applications with trojanized versions.
This campaign represents a tactical evolution from a similar attack reported by Forcepoint in early August 2025, where threat actors used a fake TradingView site to deliver the same malware.
By shifting their lure to a trusted enterprise application like Microsoft Teams, the attackers are widening their net to ensnare a broader range of victims.
The attack begins when a user lands on a fraudulent webpage designed to look like a Microsoft security verification page for Teams. The page instructs the user to resolve a supposed “Unusual Web Traffic” issue by copying a command and pasting it into their macOS Terminal.
While the page displays a seemingly harmless command, the “Copy” button actually places a malicious, base64-encoded AppleScript payload onto the user’s clipboard. When an unsuspecting user executes this command, they unwittingly launch the Odyssey stealer.
Once active, the malware initiates a multi-stage process to compromise the system thoroughly:
out.zip in a temporary directory. This file is then sent to a command-and-control (C2) server located at the IP address 185.93.89.62. The same server hosts the login panel for the Odyssey stealer toolkit.The consequences for victims are severe, ranging from credential theft and data breaches to significant financial losses from compromised cryptocurrency wallets. The persistence mechanism means that even after a one-time data theft, the system remains compromised and vulnerable to further attacks.
To defend against this threat, security experts recommend the following measures:
/Library/LaunchDaemons/ for suspicious files and look for recent, unexpected osascript executions.Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…