Fake Crypto Wallet App Delivers PamStealer Malware That Hijacks Mac Credentials
A new PamStealer variant for macOS spreads via a fake crypto wallet, using server-assisted decryption to steal credentials, Keychain data, and crypto assets.
A new variant of the macOS infostealer PamStealer is being distributed through a fake cryptocurrency wallet application called Wavel. This version uses a Swift-based payload with server-assisted decryption, making static analysis difficult. Once executed, it steals credentials, Keychain data, browser information, and cryptocurrency wallet files, and it validates passwords using macOS PAM before exfiltration. The malware establishes persistence through multiple mechanisms, including a LaunchAgent that masquerades as a Finder component.