
PamStealer macOS Malware Evolves with Server-Side Decryption and Live C2 Interaction
CybersecurityMalwaremacOSCommand and Control
Cybersecurity researchers have identified a new version of PamStealer macOS malware that implements server-side decryption to recover the main payload. According to Jamf Threat Labs, the latest variants continue using the same JavaScript for Automation (JXA) dropper mechanism while modifying the lure and delivery method. Earlier variants of PamStealer embedded their payload key material differently than the current version, which now requires live command-and-control server interaction for payload decryption.