EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Editorial source
Editorial OSINT source. The content is an indication to verify with independent institutional or technical sources before operational decisions.
EudorIA operational summary

What it means

Priority 85/100

PamStealer, un malware macOS, è stato aggiornato per utilizzare una catena di decrittazione server-side e persistenza multi-livello. L'attacco si basa su un dropper JXA che scarica un'utilità di decrittazione e esegue un'exchange di chiavi X25519. Il payload è protetto da una chiave privata server-side, rendendo difficile la decrittazione statica. La persistenza è garantita tramite LaunchAgent, script di riparazione e hook shell.

Why it matters

Per le PMI italiane, il rischio è elevato poiché il malware mira a rubare credenziali da browser e sistemi di autenticazione. La complessità del payload e la dipendenza dal C2 rendono difficile la rilevazione e la mitigazione, aumentando la vulnerabilità a attacchi mirati.

Potential operational benefits

  • Riduzione della superficie esposta
  • Maggiore visibilità su attività sospette
  • Prevenzione di attacchi mirati
  • Riduzione del rischio di furto di credenziali
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsFirewall NGFW / IPSEDR / XDRMonitoraggio / SIEMPatch managementSegmentazione di rete
AudienceITSOCCISO
Information centre

Translation in progress

The Hacker News

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material

Source
The Hacker News
Publishing entity
The Hacker News
Entity type
editorial osint
Area
Global
Original language
en · translation in preparation
Publication
25/09/2026 15:18
MITRE ATT&CK
T1190, T1078, T1486
Open the original source