Skip to content
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi

Ground.News • September 26, 2026

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material

There is no tracked Bias information for the sources covering this story.

To view factuality data please Upgrade to Premium

To view ownership data please Upgrade to Vantage

Extracted Entities

Attack Types (1)

Malware (1)

Platforms (1)