Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

    September 27, 2026

    An OpenAI Agent Hacked An Australian Government Site To Answer A Question

    September 27, 2026

    The polite way to use your phone around other people, explained

    September 27, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
    Cybersecurity

    PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

    InfoForTechBy InfoForTechSeptember 26, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Ravie LakshmananSep 25, 2026Malware / Social Engineering

    Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain.

    The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method.

    “Where earlier variants embedded their payload key material directly in the JXA source, it now fetches a purpose-built decryption utility and completes a key exchange with the server before the payload can be unwrapped,” security researcher Thijs Xhaflaire said in an analysis. “Without the server’s cooperation, the payload cannot be recovered statically.”

    A second major change is the choice of the decoy itself. While previous versions observed in July and August 2026 were observed using fake websites masquerading as Maccy, Scoppr, and Nancy Clipboard, victims are now lured through a bogus website (“wavel[.]app”) advertising a non-existent cryptocurrency wallet service named Wavel.

    Clicking the “Download for macOS” button on the fake site leads to the retrieval of a disk image file (“Wavel.dmg”) that contains a compiled AppleScript file. Opening the file launches Apple’s built-in Script Editor with instructions to trigger the execution of a JXA dropper.

    “In Maccy, Scoppr and Nancy, the JXA source performed RC4 decryption of an embedded payload, made Objective-C framework calls through JXA’s bridge to Foundation and NSData, and managed the entire download and staging process,” Xhaflaire explained.

    “In Wavel, the JXA source contains none of that. The entire JXA layer is now a carrier. When Script Editor executes the file, it decodes the base64 string and pipes the result into /bin/zsh -s, where zsh reads and executes the decoded bytes from standard input. The JXA process exits immediately; the zsh dropper continues in the background.”

    The decoded zsh script is takes the infection forward by carrying out the following actions –

    • Downloading and invoking the “pkgunpack” decryption utility from “wavel.apple03cloudstore[.]com”
    • Performing the X25519 key exchange
    • Decrypting and staging the payload bundle
    • Suppressing macOS notifications that alert users when a new background login item is added
    • Installing four redundant persistence methods via LaunchAgent, a repair zsh script that restores both the payload bundle and the LaunchAgent if not present, and a shell hook appended to ~/.zshrc that triggers the execution of the repair script on every new interactive zsh session
    • Polling for and uploading the staging directory in the form of a ZIP archive

    Because the server holds the private key that completes the key exchange process, the Data Encryption Key (DEK) cannot be recovered without it, thereby preventing the payload from being decrypted. Furthermore, given that a new ephemeral keypair is generated during every execution, a captured DEK value cannot be replayed to extract the contents of the payload.

    This, in turn, renders the encrypted payload effectively useless for static analysis without access to a live command-and-control (C2) session.

    Ephemeral key generation and a live DEK exchange

    What’s more, the repair script is copied to “post-checkout” and “pre-commit” folders within “~/Library/Application Support/System/.githooks/,” with the Git configuration option “git config –global core.hooksPath” set to the directory. As a result, any git checkout or git commit action in any repository on the compromised system will silently activate the repair script.

    The final stage is the stealer component written in Swift, marking a departure from the predecessor, which was implemented in Rust. Despite the change in the programming language used, the end goal is the same –

    • Capture system password by serving a fake crash dialog and cross-checks the entered information using a PAM-based validation approach
    • Enumerate and retrieve keychain items
    • Steal credentials from Chromium- and Firefox-based browsers, including Google Chrome, Microsoft Edge, Mozilla Firefox, Brave, Vivaldi, Opera, Opera GX, Arc, Zen, Waterfox, LibreWolf, Yandex Browser, and Cốc Cốc
    • Fingerprint the system and gather extensive metadata and user’s profile photo
    • Collect user-centric files like .zsh_history, .zshrc, .bash_history and .gitconfig
    • List running processes and installed applications

    “The inclusion of Arc, Zen and the less common regional and privacy-focused browsers extends the target list noticeably beyond what is typical in commodity macOS stealers,” Xhaflaire said.

    “This variant of PamStealer reflects a deliberate investment in delivery infrastructure. The pkgunpack utility introduces a live key exchange that ties payload decryption to server availability: without C2 cooperation, the second stage cannot be decrypted. That design makes static recovery of the payload significantly harder and shifts part of the operational control to the server operator.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

    September 27, 2026

    Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

    September 26, 2026

    Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

    September 25, 2026

    Top 10 CNAPP Vendors for Enterprises

    September 25, 2026

    Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

    September 25, 2026

    Why Hacking Is No Longer Just About Code

    September 24, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026394 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202641 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202637 Views

    How is Luckin Coffee expanding rapidly in S’pore while keeping its coffee so cheap?

    April 23, 202625 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026394 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202641 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202637 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.