PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
PamStealer has appeared in a new macOS variant that uses a server-side decryption chain, making the payload impossible to recover statically without live C2 cooperation. The campaign lures victims through a fake Wavel cryptocurrency wallet site and ultimately steals passwords, keychain items, browser credentials, and system data from compromised Macs. #PamStealer #Wavel #JamfThreatLabs #macOS

Keypoints

  • The new PamStealer version relies on a server-side decryption chain for payload recovery.
  • A fake Wavel website delivers the malicious Wavel.dmg file to macOS victims.
  • The JXA layer now acts only as a carrier before handing execution to a zsh dropper.
  • The attack uses pkgunpack, X25519 key exchange, and ephemeral keys to block static analysis.
  • The Swift stealer collects passwords, keychain items, browser credentials, and system metadata.

Read More: https://thehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html