hacker-news · Crawled Sep 25, 2026

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

5 IoCs
Read original article ↗

AI Summary

A new variant of the PamStealer macOS malware has been identified, featuring live command-and-control (C2) payload decryption and multi-layer persistence mechanisms. The malware is distributed via a fake cryptocurrency wallet website (wavel[.]app), which delivers a malicious disk image containing a compiled AppleScript that executes a JXA dropper. The dropper initiates a key exchange with the C2 server using X25519 to decrypt the payload, preventing static analysis. The malware employs four persistence methods, including LaunchAgent, shell hooks, and Git hooks, and ultimately deploys a Swift-based stealer to harvest credentials, browser data, keychain items, and system metadata.

AI-extracted · verify before operational use

Indicators of Compromise 5 extracted

Type Value Detail
Domain wavel[.]app Details →
Domain wavel[.]apple03cloudstore[.]com Details →
Filename Wavel.dmg Details →
Filename post-checkout Details →
Filename pre-commit Details →