New PamStealer macOS Variant Employs Server‑Side Decryption and Multi‑Stage Persistence
Cybersecurity analysts at Jamf Threat Labs have identified an upgraded version of the PamStealer malware targeting macOS computers, adding a live command‑and‑control (C2) decryption step and a layered persistence mechanism.
The updated strain encrypts its primary payload on the victim machine and requires a server‑side decryption chain to reconstruct the malicious code, effectively preventing static analysis tools from extracting the payload without contacting the attacker’s infrastructure.
Despite the new encryption layer, the malware still relies on a JavaScript for Automation (JXA) dropper that has been observed in earlier samples. The dropper executes native macOS commands and sets up additional components, allowing the threat actor to maintain a foothold even after system reboots or basic remediation attempts.
Researchers note that the multi‑layer persistence approach combines several techniques, such as creating launch agents, modifying login items, and leveraging hidden plist files. By spreading its presence across multiple system entry points, PamStealer can survive typical cleanup actions and re‑establish communication with its C2 server.
The emergence of this variant underscores a broader trend of macOS‑focused threat actors adopting more sophisticated evasion tactics previously seen primarily in Windows‑based malware. As Apple’s market share continues to grow, attackers are investing in tools that can bypass built‑in security features like Gatekeeper and notarization.
Jamf Threat Labs recommends that organizations using macOS devices enforce strict code‑signing policies, monitor for anomalous JXA execution, and deploy endpoint detection solutions capable of identifying encrypted payload delivery patterns. Ongoing observation of PamStealer’s C2 infrastructure will help security teams develop signatures and block indicators of compromise before the malware can exfiltrate data or further entrench itself.
Comments (0)
Be the first to comment.
Join the discussion