Back
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
SiTech AI Team2 წთ. საკითხავი

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

A new PamStealer variant spreads through a fake Wavel crypto wallet site and keeps its second stage encrypted until the malware talks to its command server, Jamf Threat Labs says.

Cybersecurity researchers have flagged a new version of PamStealer, a macOS information stealer, that can recover its main payload only with help from an attacker-controlled server. The artifacts were analyzed by Jamf Threat Labs, which documented the family's earlier variants in July and August 2026.

A fake wallet and a lighter dropper

Earlier campaigns lured victims with sites impersonating Maccy, Scoppr and Nancy Clipboard. The new wave uses a bogus site, wavel[.]app, advertising a non-existent cryptocurrency wallet service called Wavel. Its "Download for macOS" button delivers Wavel.dmg, a disk image holding a compiled AppleScript file. Opening it launches Apple's Script Editor, which asks the user to run a JXA dropper; that layer now only decodes a base64 string and pipes the result into /bin/zsh -s, then exits while the shell script continues in the background.

Decryption bound to the C2 server

The shell script downloads a purpose-built utility called pkgunpack from wavel.apple03cloudstore[.]com, performs an X25519 key exchange and only then decrypts the second-stage payload. "Without the server's cooperation, the payload cannot be recovered statically," said Jamf researcher Thijs Xhaflaire. The server holds the private key that completes the exchange, and a fresh ephemeral keypair is generated on every execution, so a captured key cannot be replayed. Without a live command-and-control session, the encrypted payload is of little use for static analysis.

Four persistence layers and a Swift stealer

Before settling in, the dropper suppresses macOS notifications about new background login items and installs four redundant mechanisms: a LaunchAgent, a repair zsh script that restores the payload bundle and the agent if they are missing, a hook appended to ~/.zshrc that triggers the repair on every new interactive shell session, and Git hooks. With git config --global core.hooksPath pointed at its own directory, any git checkout or commit silently runs the repair script. Staged data is then uploaded as a ZIP archive.

The final stage has been rewritten in Swift, replacing the Rust stealer of earlier variants. It captures the system password through a fake crash dialog and validates it via PAM, then harvests Keychain items and credentials from Chromium- and Firefox-based browsers, including Chrome, Edge, Firefox, Brave, Vivaldi, Opera, Opera GX, Arc, Zen, Waterfox, LibreWolf, Yandex Browser and Cốc Cốc. It also collects shell histories, Git configuration, installed applications and the user's profile photo.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.