< BACK TO NEWS
importantSYS.SOURCE: The Hacker News• 2026-09-25T18:48:06+05:30

PamStealer macOS Malware Implements Live C2 Decryption and Enhanced Persistence Mechanisms

PamStealer macOS malware now employs live C2 payload decryption requiring server-side key exchange, making static analysis infeasible. It implements multi-layer persistence through LaunchAgent, Git hooks, and a Swift-based stealer component targeting extended browser ecosystems.

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain.

The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method.

"Where earlier variants embedded their payload key material

Read original article

*** END OF TRANSMISSION ***