Newly discovered PamStealer isn’t your typical macOS malware

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Researchers at Jamf have discovered PamStealer, a novel macOS infostealer that uses a multi-stage delivery chain to evade detection. It arrives disguised as the Maccy clipboard manager in a disk image, uses an AppleScript lure that bypasses macOS quarantine via Command-R execution, and drops a Rust-written second stage that leverages macOS's Pluggable Authentication Modules (PAM) to locally validate stolen credentials before exfiltrating them. The second stage impersonates Finder, encrypts C2 traffic, and deliberately delays prompts like Full Disk Access requests by up to 40 minutes to avoid correlation with launch time — making it significantly stealthier than typical commodity macOS stealers.

3m read timeFrom arstechnica.com
Post cover image
Table of contents
Ars Video
1K Impressions