Odyssey Stealer: Technical Analysis of a macOS Infostealer
Executive Summary In mid‑July 2026, I obtained a macOS infostealer trojan disguised as a software licensing tool (Patch.app). The sample is a Mach‑O universal binary (x86_64 + arm64) that leverages a custom xorshift32 PRNG‑based XOR cipher to obfuscate 379 embedded strings. Upon execution, it harvests credentials from 14 browsers, 17...
Continue reading