[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9-fGqSWNkHP9Y6sGT55Pcd43wzTkhvJeuCcbHZLyGm4":3},{"article":4,"iocs":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"d900ab98-9a74-458f-aa60-45ab4e69002a","PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence","pamstealer-macos-malware-adds-live-c2-payload-decryption-and-multi-layer-persist-4731c3","Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. \"Where earlier variants embedded their payload key material","A new variant of the PamStealer macOS malware has been identified, featuring enhanced evasion techniques. It now employs a server-side decryption chain for its main payload, requiring a live command-and-control (C2) session for decryption. The malware also utilizes a new lure, a fake cryptocurrency wallet service named Wavel, and implements multiple redundant persistence mechanisms, including Git hooks, to ensure its continued operation on compromised systems.","PamStealer macOS malware evolves with live C2 payload decryption and multi-layer persistence.","PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence Ravie LakshmananSep 25, 2026Malware \u002F Social Engineering Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. \"Where earlier variants embedded their payload key material directly in the JXA source, it now fetches a purpose-built decryption utility and completes a key exchange with the server before the payload can be unwrapped,\" security researcher Thijs Xhaflaire said in an analysis. \"Without the server's cooperation, the payload cannot be recovered statically.\" A second major change is the choice of the decoy itself. While previous versions observed in July and August 2026 were observed using fake websites masquerading as Maccy, Scoppr, and Nancy Clipboard, victims are now lured through a bogus website (\"wavel[.]app\") advertising a non-existent cryptocurrency wallet service named Wavel. Clicking the \"Download for macOS\" button on the fake site leads to the retrieval of a disk image file (\"Wavel.dmg\") that contains a compiled AppleScript file. Opening the file launches Apple's built-in Script Editor with instructions to trigger the execution of a JXA dropper. \"In Maccy, Scoppr and Nancy, the JXA source performed RC4 decryption of an embedded payload, made Objective-C framework calls through JXA's bridge to Foundation and NSData, and managed the entire download and staging process,\" Xhaflaire explained. \"In Wavel, the JXA source contains none of that. The entire JXA layer is now a carrier. When Script Editor executes the file, it decodes the base64 string and pipes the result into \u002Fbin\u002Fzsh -s, where zsh reads and executes the decoded bytes from standard input. The JXA process exits immediately; the zsh dropper continues in the background.\" The decoded zsh script is takes the infection forward by carrying out the following actions - Downloading and invoking the \"pkgunpack\" decryption utility from \"wavel.apple03cloudstore[.]com\" Performing the X25519 key exchange Decrypting and staging the payload bundle Suppressing macOS notifications that alert users when a new background login item is added Installing four redundant persistence methods via LaunchAgent, a repair zsh script that restores both the payload bundle and the LaunchAgent if not present, and a shell hook appended to ~\u002F.zshrc that triggers the execution of the repair script on every new interactive zsh session Polling for and uploading the staging directory in the form of a ZIP archive Because the server holds the private key that completes the key exchange process, the Data Encryption Key (DEK) cannot be recovered without it, thereby preventing the payload from being decrypted. Furthermore, given that a new ephemeral keypair is generated during every execution, a captured DEK value cannot be replayed to extract the contents of the payload. This, in turn, renders the encrypted payload effectively useless for static analysis without access to a live command-and-control (C2) session. Ephemeral key generation and a live DEK exchange What's more, the repair script is copied to \"post-checkout\" and \"pre-commit\" folders within \"~\u002FLibrary\u002FApplication Support\u002FSystem\u002F.githooks\u002F,\" with the Git configuration option \"git config --global core.hooksPath\" set to the directory. As a result, any git checkout or git commit action in any repository on the compromised system will silently activate the repair script. The final stage is the stealer component written in Swift, marking a departure from the predecessor, which was implemented in Rust. Despite the change in the programming language used, the end goal is the same - Capture system password by serving a fake crash dialog and cross-checks the entered information using a PAM-based validation approach Enumerate and retrieve keychain items Steal credentials from Chromium- and Firefox-based browsers, including Google Chrome, Microsoft Edge, Mozilla Firefox, Brave, Vivaldi, Opera, Opera GX, Arc, Zen, Waterfox, LibreWolf, Yandex Browser, and Cốc Cốc Fingerprint the system and gather extensive metadata and user's profile photo Collect user-centric files like .zsh_history, .zshrc, .bash_history and .gitconfig List running processes and installed applications \"The inclusion of Arc, Zen and the less common regional and privacy-focused browsers extends the target list noticeably beyond what is typical in commodity macOS stealers,\" Xhaflaire said. \"This variant of PamStealer reflects a deliberate investment in delivery infrastructure. The pkgunpack utility introduces a live key exchange that ties payload decryption to server availability: without C2 cooperation, the second stage cannot be decrypted. That design makes static recovery of the payload significantly harder and shifts part of the operational control to the server operator.\" Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Credential Theft, MacOS, Malware, Social Engineering ⚡ Top Stories This Week Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. How to Evaluate a Unified Security Platform Using a One-Incident Test Stop Trying to Control AI Behavior. Control What AI Can Reach ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fpamstealer-macos-malware-adds-live-c2.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEiRZ3gQjU3cKnH6bHzlz8PjeaUqGcrVWnRx-bT-mgDBYv-G4CM2Iix8afTJe8sAXEghuPTiD5KszOYzA0peRhyoGKNW9YE1QtwLubBFuv9YZjXnANEGyMGwi7-oEdIqmtRBWPzUZV7S91WiUX4cI2YVMHVSQbByCmIwAX9oZxvzjb2ScVJmpmMCzpDKaKtN\u002Fs1600\u002Fmacos.jpg","2026-09-25T13:18:06+00:00","2026-09-25T20:01:00.197247+00:00",8,[18,21,24,26,28,30],{"name":19,"type":20},"macOS","product",{"name":22,"type":23},"JavaScript for Automation (JXA)","technology",{"name":25,"type":23},"AppleScript",{"name":27,"type":23},"LaunchAgent",{"name":29,"type":23},"PAM",{"name":31,"type":32},"Jamf","vendor","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":33,"icon":35,"name":36,"slug":37},null,"Malware","malware",[39,44,46],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":45},{"id":33,"icon":35,"name":36,"slug":37},{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[52,56,59],{"type":53,"value":54,"context":55},"domain","wavel[.]app","Fake cryptocurrency wallet service domain used for lure.",{"type":53,"value":57,"context":58},"wavel.apple03cloudstore[.]com","Command and control domain for downloading decryption utility.",{"type":37,"value":60,"context":61},"PamStealer","Name of the macOS malware family."]