PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Executive Summary

Cybersecurity researchers identified a new PamStealer variant for macOS that forces the main payload to be recovered via a server‑side decryption chain. The malware still uses a JavaScript for Automation (JXA) dropper but changes its lure and delivery method, and introduces multi‑layer persistence. Earlier versions embedded key material directly, whereas this version relies on external decryption.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-25T13:18:06+00:00 - Category: threat-intel

Original Description: Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material

"Kindness is the language which the deaf can hear and the blind can see."

— Mark Twain
Source: The Hacker News