PamStealer macOS Malware Adds Live Decryption and Multi-Layer Persistence

Security camera undergoing privacy-mask persistence and configuration-drift testing

Jamf Threat Labs has documented a new PamStealer macOS campaign that changes how the main payload is recovered and persisted. The operation uses a bogus cryptocurrency-wallet site and an AppleScript-based lure, while payload decryption depends on communication with attacker-controlled infrastructure.

Server-assisted decryption limits static recovery

Earlier variants embedded more of the decryption material in the initial script. Jamf reported that the newer Wavel-themed chain downloads a purpose-built utility and completes a key exchange before the payload can be unpacked. Without the server’s cooperation, analysts cannot recover the final component from the first-stage file alone.

The victim is directed to open a disk image and run an AppleScript through Script Editor. A JavaScript for Automation carrier then hands execution to a shell process. The campaign relies on user action and abuse of trusted operating-system tools rather than a single remote exploitation step.

Persistence and credential exposure widen the impact

The reported chain installs multiple persistence mechanisms and seeks browser, wallet and account information. Defenders should preserve the initial lure, process tree, downloaded utilities and network destinations because any one layer may disappear after infrastructure changes.

Endpoint monitoring should flag unusual Script Editor-to-shell execution, new launch items and unsigned utilities retrieved from recently registered infrastructure. These controls complement the identity and endpoint concerns covered under Cyber-Physical Security. Users should install software only from verified vendor channels and avoid executing scripts presented by download pages.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *