PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain.

The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method.

“Where earlier variants embedded their payload key material

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Kagi Changelog (July 2): Heads, tails, and an AI toggle

Kagi Changelog (July 2): Heads, tails, and an AI toggle Source: Hacker News

Launch HN: Mireye (YC S26) – Infrastructure for Physical World AI Agents

Launch HN: Mireye (YC S26) – Infrastructure for Physical World AI Agents Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 31.08.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 695 requests (recent log) 34.68.39.29 — 668 requests (recent log) 34.70.129.79 — 483 requests (recent