Skip to content
New PamStealer Variant Targets macOS with Live C2 Decryption

New PamStealer Variant Targets macOS with Live C2 Decryption

First seen 26 Sep 2026, 11:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 16:34 UTC
  • •PamStealer now uses server-side decryption, complicating static analysis.
  • •Victims are lured via a fake cryptocurrency wallet site, 'wavel[.]app.'
  • •The malware installs multiple persistence methods to ensure ongoing access.

A new version of the PamStealer malware has been identified, which utilizes a server-side decryption mechanism to obscure its main payload, making static analysis difficult. The malware, discovered by Jamf Threat Labs, employs a JavaScript for Automation (JXA) dropper and has changed its delivery method to lure victims through a fake cryptocurrency wallet website named 'wavel[.]app.' Upon downloading a disk image file, victims execute an AppleScript that triggers the JXA dropper, which then decodes a base64 string and executes a zsh script. This script downloads a decryption utility and performs a key exchange with a command-and-control server, ensuring the payload remains undecryptable without server access. The malware installs multiple persistence methods to maintain its presence on infected systems. It targets various browsers, aiming to steal passwords and sensitive user data.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-25
PamStealer variant identified
A new PamStealer variant was reported using server-side decryption, complicating recovery of its payload.
The Hacker News
2026-09-26
Multiple reports published
Several cybersecurity outlets reported on the new PamStealer variant, confirming its attack methods and persistence mechanisms.
Cybernoz
2026-09-26
Malware's impact detailed
Reports highlighted the malware's ability to target various browsers and steal sensitive user data.
Scworld

More articles in this cluster (6)

Following this threat?

Track PamStealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed