Background and Timeline: Reported on February 10, 2026, a new and aggressive malware campaign identified as “Odyssey Stealer” has begun targeting Apple computers globally. The malware has seen a sharp uptick in infections during the first week of February. This follows a trend where Mac-specific threats are becoming as prevalent as those targeting Windows systems.
Modus Operandi: Odyssey Stealer is delivered primarily through malicious third-party applications or fake software updates that masquerade as legitimate tools. Once installed, the malware conducts a thorough sweep of the victim’s device to exfiltrate login credentials, sensitive personal documents, and cryptocurrency wallet keys. The malware uses sophisticated evasion techniques to bypass standard macOS security protocols.
Victims and Financial Impact: While the exact number of victims has not been publicized, the malware targets high-value individuals who store digital assets and sensitive professional data on Mac computers. The exfiltration of cryptocurrency keys represents an immediate financial risk for individual investors. Secondary victims include the organizations whose internal documents are stolen during the breach of employee-owned devices.
Investigation and Agencies Involved: Cybersecurity researchers from multiple firms, including Cyderes and Kaspersky, are tracking the campaign’s C2 infrastructure. They have linked the distribution to servers that also host malicious VS Code extensions and pirated video games. Analysts have warned that “Odyssey” reflects a shift toward more professionalized development of macOS malware.
Arrests and Suspects: No specific individuals have been arrested, though technical signatures link the malware to threat actors operating from Eastern Europe. These groups are known for specializing in information stealers that feed stolen credentials into automated account-takeover bots. The investigation is currently focusing on the primary distribution sites for the “fake software updates” used to deliver the payload.
Broader Implications and Trends: The rise of Odyssey Stealer proves that Apple’s hardware and software are no longer a safe haven from professional malware syndicates. It underscores the need for Mac users to adopt hardware-based security keys and avoid all unofficial software sources. This incident reflects the broader 2026 trend where “cross-platform” attacks are the new standard for info-stealers.