Thehackernews New PamStealer Variant Targets macOS with Live C2 Decryption
Article Content
- •PamStealer now uses server-side decryption, complicating static analysis.
- •Victims are lured via a fake cryptocurrency wallet site, 'wavel[.]app.'
- •The malware installs multiple persistence methods to ensure ongoing access.
A new version of the PamStealer malware has been identified, which utilizes a server-side decryption mechanism to obscure its main payload, making static analysis difficult. The malware, discovered by Jamf Threat Labs, employs a JavaScript for Automation (JXA) dropper and has changed its delivery method to lure victims through a fake cryptocurrency wallet website named 'wavel[.]app.' Upon downloading a disk image file, victims execute an AppleScript that triggers the JXA dropper, which then decodes a base64 string and executes a zsh script. This script downloads a decryption utility and performs a key exchange with a command-and-control server, ensuring the payload remains undecryptable without server access. The malware installs multiple persistence methods to maintain its presence on infected systems. It targets various browsers, aiming to steal passwords and sensitive user data.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track PamStealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed