hacker-news · Crawled Sep 25, 2026
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
5 IoCs
Read original article ↗
AI Summary
A new variant of the PamStealer macOS malware has been identified, featuring live command-and-control (C2) payload decryption and multi-layer persistence mechanisms. The malware is distributed via a fake cryptocurrency wallet website (wavel[.]app), which delivers a malicious disk image containing a compiled AppleScript that executes a JXA dropper. The dropper initiates a key exchange with the C2 server using X25519 to decrypt the payload, preventing static analysis. The malware employs four persistence methods, including LaunchAgent, shell hooks, and Git hooks, and ultimately deploys a Swift-based stealer to harvest credentials, browser data, keychain items, and system metadata.
AI-extracted · verify before operational use