πŸ€– New PamStealer macOS variant decrypts its payload live from C2 and adds multi-layer persistence. JXA dropper updated with new lure and delivery, per Jamf Threat Labs. πŸ”— https:// thehackernews.com/

πŸ€– New PamStealer macOS variant decrypts its payload live from C2 and adds multi-layer persistence. JXA dropper updated with new lure and delivery, per Jamf Threat Labs.

3 reportsother

Claim audit

No BS check run yet β€” press βš– to extract this story's claims and verify them against independent sources.

All coverage

πŸ€– New PamStealer macOS variant decrypts its payload live from C2 and adds multi-layer persistence. JXA dropper updated with new lure and delivery, per Jamf Threat Labs. πŸ”— https:// thehackernews.com/

mastodon:infosec-exchangeother4d ago kagi β†—

πŸ€– New PamStealer macOS variant decrypts its payload live from C2 and adds multi-layer persistence. JXA dropper updated with new lure and delivery, per Jamf Threat Labs. πŸ”— https:// thehackernews.com/2026/09/pams tealer-macos-malware-adds-live-c2.html # Malware # ReverseEngineering # CyberSec

πŸ€– PamStealer macOS stealer evolved: the payload is now unwrapped through a server-side key exchange, so it can't be decrypted statically without C2 cooperation. Lure switched from fake clipboard apps

mastodon:infosec-exchangeother3d ago kagi β†—

πŸ€– PamStealer macOS stealer evolved: the payload is now unwrapped through a server-side key exchange, so it can't be decrypted statically without C2 cooperation. Lure switched from fake clipboard apps to wavel[.]app, a bogus crypto wallet whose DMG drops a JXA loader piped into /bin/zsh -s. Analysis by Jamf Threat Labs. πŸ”— https:// thehackernews.com/2026/09/pams tealer-macos-malware-adds-live-c2.h