Cybersecurity experts have uncovered a well-organized and sophisticated malware campaign targeting macOS. The Poseidon Stealer software is distributed via a fake website that simulates the DeepSeek AI.
See also: New distribution campaigns of info-stealer malware Lumma and ACR Stealer

This malware as a service (MaaS) leverages sophisticated social engineering techniques combined with anti-analysis methods, putting sensitive user data at risk. This is a significant escalation in threats targeting macOS, increasing the challenges for system security
The Poseidon Stealer attack chain begins with malicious advertising campaigns that redirect users to the website deepseek.exploreio[.]net. This domain hosts a near-perfect imitation of the legitimate DeepSeek AI interface, thereby misleading unsuspecting users.
When users click “Download for MacOS,” they download a DMG file named DeepSeek_v.[0-9].[0-9]{02}.dmg from the compromised website manyanshe[.]com. The attached DMG contains a malicious shell script, which is deceptively presented as an application package.
See also: Infostealer malware impersonates DeepSeek tools on PyPI
This complex multi-stage payload leverages osascript to execute AppleScript commands, bypassing macOS Gatekeeper. Through this process, it achieves forced execution of commands via the terminal.

The script copies a binary file named .DeepSeek to the /tmp directory, removes all extended attributes using the xattr -c , and makes it executable with the chmod +x.
Poseidon Stealer has advanced multi-layered anti-debug measures. An additional control mechanism leverages the sysctl function to check the P_TRACED in the process status, thus enhancing efficiency and detecting potential threats.
The malware is disabled when usernames match known researcher aliases, such as “maria” or “jackiemac,” through the AppleScript validation process.
See also: GitHub: Fake PoC exploit for infostealer vulnerability is being distributed
Stealer malware is a serious threat in the world of cybersecurity, as it is designed to steal sensitive information from users. This type of malware can target data such as passwords, bank account information, credit card data, and other valuable items stored on devices or web browsers. Attackers use Stealer malware to gain unauthorized access to personal or corporate information, often causing financial losses or privacy violations for victims. Understanding how to prevent it, such as using up-to-date security software and paying attention to suspicious emails or links, is critical to protecting against these types of threats.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
