PamStealer macOS Malware Adds Live C2 Payload Decryption and MultiLayer Persistence
News Source : Internet
News Summary
- Researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain.
- The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method.
- While previous versions observed in July and August 2026 were observed using fake websites masquerading as Maccy, Scoppr, and Nancy Clipboard.
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a serverside decryption chain.
Never miss a story from us, subscribe to our newsletter