PamStealer macOS Malware Adds Live C2 Payload Decryption and MultiLayer Persistence

Image for article PamStealer macOS Malware Adds Live C2 Payload Decryption and MultiLayer Persistence
News Source : Internet

News Summary

  • Researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain.
  • The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method.
  • While previous versions observed in July and August 2026 were observed using fake websites masquerading as Maccy, Scoppr, and Nancy Clipboard.
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a serverside decryption chain.

Must read Articles