PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain.

The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method.

“Where earlier variants embedded their payload key material

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Show HN: Exploiting Slack’s video embeds to achieve E2EE communication

Show HN: Exploiting Slack’s video embeds to achieve E2EE communication Source: Hacker News

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which

Attack Update: Top 5 Attack-IPs auf doode.info – 20.06.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 167.172.177.125 — 93 requests (recent log) 89.167.35.212 — 68 requests (recent log) 216.73.217.33 — 37 requests (recent