PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Updated PamStealer decrypts its macOS payload only with live C2 help and adds layered persistence.
Jamf Threat Labs describes a new PamStealer macOS variant that no longer embeds its decryption key in the JavaScript for Automation dropper. Victims are lured by wavel[.]app, a fake cryptocurrency wallet, to open Wavel.dmg; the dropper downloads pkgunpack from wavel.apple03cloudstore[.]com and completes an X25519 key exchange so the payload cannot be recovered without the server. It installs a LaunchAgent, a repair script, a ~/.zshrc hook, and Git hooks, then a Swift stealer captures the system password through a fake crash dialog, reads keychain items, and steals credentials from Chromium and Firefox browsers.