Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Security Education Videos Scams & Phishing Your Security Mobile Security Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
Mac Users Targeted by Poseidon's Trident
Facebook   X   LinkedIn   Email

Mac Users Targeted by Poseidon's Trident

March 27, 2025

Mac users are in the crosshairs again. Recently, a new campaign distributing malware targeting them via malicious Google ads for the Arc browser was observed and reported by Malwarebytes. This is the second such instance in recent months, highlighting Arc's growing use in the Mac world. Cybercriminals are riding the Arc popularity wave and pointing their cyber-trident right at MacOS users.

It isn’t the first time this method has been used to distribute a Windows RAT. This latest campaign involves a macOS stealer, branded as "Poseidon," actively developed as a competitor to Atomic Stealer (AMOS). It shares much of its code with its predecessor, formerly tracked as OSX.RodStealer by Malwarebytes, which was cleverly named after its author, Rodrigo4.

The Poseidon malware isn’t the same old malware. It goes further and adds new features such as looting VPN configurations. It is distributed via malvertising. You’ve heard of this before, most likely. It’s when malware is inserted into those advertisements you see in your browsers or in email banners. And the ads can even be legitimate business that were hijacked by the malware.

How can real businesses let their ads become compromised, you ask? Well, the advertisers don’t have control over the ads once they place them with the distributor, such as Google Ads. They are typically randomly placed, so even Google doesn’t know it’s happening until they are reported.

If you want to take a look at something you see in an ad, avoid clicking the ad, no matter how clever or flashy it is. Instead, go to the company’s website by typing it into the address bar of your browser and search for the product that way. If it is reasonable, consider using ad blocking software. Then you won’t be tempted to click on them in the first place. As always, make sure you have anti-malware software installed and it’s kept updated.

This campaign advertises Poseidon on cybercrime forums. Rodrigo4 is active on the XSS underground forum and offers a service that goes the extra customer service mile. It includes a malware panel with statistics and a builder allowing customization of the malware's name, icon, and AppleScript. Poseidon's functionalities are vast and include:

  • a file grabber
  • a browser data collector
  • a password manager stealer
  • a crypto wallet extractor

This campaign underscores the importance of vigilance against malvertising and the need for robust cybersecurity measures to protect against evolving threats, even for macOS users.


FBI Warns of Threat from North Korean APT

Corporate Security

FBI Warns of Threat from North Korean APT

A North Korean-linked APT (Advanced Persistent Threat) group recently found and exploited an email vulnerability. Documented in a joint advisory from the FBI, Department of State, and the National Security Agency (NSA), it warns of an issue with weak DMARC (Domain-based Message Authentication, Reporting & Conformance) Security policies that allow a backdoor malware. The advisory does not point to a specific threat to MacOS, but there are known instances of one called SpectralBlur. Though the advisory warns all operating systems are at risk. READ FULL STORY

We Smell Another RAT; Novel Trojan Can Really Stink Up Your Android Device

Mobile Security

We Smell Another RAT; Novel Trojan Can Really Stink Up Your Android Device

It’s gotten rather stinky for Android users. Discovered and named by Trend Micro back in June 2023, the MMRat trojan is a novel malware that is really making those devices smell ripe. It mainly takes advantage of a seldom-used communication method to steal data—particularly banking and financial data. By monitoring the phone, hackers discover periods of idleness when they can conduct real-time bank fraud. And somehow, the victims of this sneaky trick are nose-blind and don’t smell a thing while it’s all happening. READ FULL STORY

Realst Malware Preying on Mac Users Through Fake Blockchain Games

Your Security

Realst Malware Preying on Mac Users Through Fake Blockchain Games

A new cybersecurity threat has surfaced, ominously dubbed "Realst." Primarily targeting Mac users, this threat lurks in seemingly inconspicuous blockchain games. However, instead of a fun gaming experience, this malware is programmed to steal your personal data. Realst takes a smart, but deceitful approach to get to you, even looking to the future. If you play this game, they may be able to install Realst on your Mac and allow the hackers to choose their targets. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...