New macOS malware PamStealer uses PAM to validate stolen data
A previously undocumented macOS infostealer dubbed PamStealer validates victims' macOS passwords through the OS’s Pluggable Authentication Modules (PAM) before stealing them. Jamf Threat Labs researchers, who analyzed a two-stage attack chain combining AppleScript, JavaScript for Automation (JXA), and a Rust payload, report that attackers distribute PamStealer through the fake domain maccyapp[.]com, which impersonates the legitimate … The post New macOS malware PamStealer uses PAM to validate stolen data appeared first on CyberInsider.
PamStealer is a macOS infostealer that uses PAM to validate stolen data, targeting Apple Silicon Macs and silently exiting on Intel systems or devices configured for former Soviet countries. The malware steals browser credentials, cookies, cryptocurrency wallet data, clipboard contents, and keychain information.
Read the full article
This is a curated summary. The complete article is available at Cyber Insider.
