Poseidon Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
December 11, 2025
Last Seen
June 10, 2026

Poseidon is a malware family tracked across 3 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed December 11, 2025; most recent activity June 10, 2026.

Overview

Poseidon is a malware family referenced in relation to a North Korea–linked hacking operation that uses legitimate advertising networks to distribute its payloads. The use of Naver and Google Ads demonstrates a growing trend of threat actors leveraging mainstream online platforms to broaden reach and evade early detection, making Poseidon notable for its scalable distribution tactics and persistent relevance in threat landscapes.

Related Threat Clusters

Recent Intelligence Reports

  • Deceptive Installers: How Fake Apps Target macOS — Huntress · June 10, 2026
  • N. Korea-linked hacking group exploits Naver, Google ads to spread malware: report — M.Koreaherald · January 19, 2026
  • Malwarebytes Launches a New Enhanced Mac Scan Engine for Threat Protection — Mactech · December 11, 2025
  • Malwarebytes Launches New Enhanced Mac Scan Engine for Smarter, Deeper macOS ... — Morningstar · December 11, 2025
  • Malwarebytes Launches New Enhanced Mac Scan Engine for Smarter, Deeper macOS ... — Prnewswire · December 11, 2025

CVSS v3.1 Breakdown