Newly Discovered PamStealer Isn't Your Typical macOS Malware
Jamf said the malware uses AppleScript and a Rust-based second stage to bypass macOS protections and steal passwords, with a fake Maccy site hosting the lure.
- Security researchers discovered PamStealer, a new macOS malware that masquerades as the legitimate clipboard manager Maccy to harvest user login credentials.
- Distributed in a disk image, the malware tricks users into executing malicious code hidden within an AppleScript file, which installs the payload onto the device.
- Utilizing a Rust-based second stage, the malware masquerades as Finder and stays hidden for up to forty minutes, effectively bypassing standard macOS security features.
- Using the Pluggable Authentication Modules interface, PamStealer validates stolen credentials locally and sends the data to an attacker-controlled server.
- Users can mitigate risks by verifying website URLs, utilizing the Apple App Store, and relying on built-in security features like XProtect.
13 Articles
13 Articles
Newly discovered PamStealer isn't your typical macOS malware
Researchers have found a never-before-seen piece of macOS malware that combines a series of clever tradecraft to infect Macs with stealthy, custom-developed credential-stealing code. The malware is delivered in two stages. The first is distributed in a disk image that masquerades as Maccy, a clipboard manager for Macs. It’s compiled as AppleScript that is notable for the way it delivers the second stage. The malware is named PamStealer because t…
The idea that Apple computers are completely protected against malware no longer corresponds to reality. Although macOS has several layers of security, criminals have developed increasingly sophisticated campaigns to circumvent these protections by exploiting the user's own behavior. PamStealer's case, a new malware directed at macOS, shows how modern attacks combine social engineering, native code and circumvention techniques to compromise syst…
Jamf Threat Labs warns of a new malware that users of the Clipboard Manager "Maccy" should watch out for. The malware called "PamStealer" is spread over malicious websites that claim to be the real Maccy website, and contains files for downloading that make visitors feel like legitimate Maccy files. The fake files are Applescript files with the extension "Maccy.scpt" designed to look like legitimate installation files and spread over disk images.
PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
Cybersecurity researchers have flagged a new macOS information stealer called PamStealer that employs a series of clever tricks to infect systems and siphon sensitive data. The stealer, discovered by Jamf Threat Labs, is distributed as a compiled AppleScript (.scpt) file impersonating Maccy, a legitimate open-source clipboard manager. It has been codenamed PamStealer owing to its ability to
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium














