Skip to main content
See every side of every news story
Published • loading... • Updated

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Summary by cybernoz.com
Ravie LakshmananSep 25, 2026Malware / Social Engineering Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and
DisclaimerRead with caution - this story is only being covered by one news source that has a ‘low factuality’ rating, which means the outlet has a history of poor reporting practices. Learn more about factuality ratings here.

4 Articles

Lean Right

In the ever-evolving world of cybersecurity, new PamStealer malware poses a growing threat to macOS users. This article examines the latest updates to its mechanisms and techniques. New Malware: PamStealer on macOS. Cybersecurity researchers have reported a new version of PamStealer that ensures the key payload can only be recovered using a server-side decryption string. Delivery Mechanism and Modification: According to Jamf Threat Labs, the lat…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources lean Right
100% Right

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

The Hacker News broke the news on Friday, September 25, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal