Skip to content

lab

Jamf Threat Labs

Threat research team credited as the original publisher of the AmnesiaStealer analysis and of the macOS 26 TCC bypass testing.

Known aliases

  • Jamf
  • Jamf researchers

Relationships

No evidence-backed relationships are recorded.

Current stories

security5 publishers

Fake Zoom installer talks macOS users past Gatekeeper to drop CloudSyncD backdoor

Jamf Threat Labs reported CloudSyncD, a new macOS backdoor that spreads through a fake Zoom installer and beacons to its server every 8 to 16 seconds. First caught as a VirusTotal sample that looked unfinished, it now appears in builds that connect to live infrastructure in what Jamf calls an active campaign.

Perspective Coverage

5 publishers
Builder
Builder 25%
Operator
Operator 70%
Investor
Investor 5%

Reality

Evidence70
Adoption15
Hype gap+15
Incentives
Insufficient
Confidence68
security5 publishers

AmnesiaStealer trades smash-and-grab for a live seat in the victim's browser

Jamf Threat Labs says the Rust macOS stealer pastes itself in via Terminal, fakes an Installer password prompt, mutes the speakers, then hands the operator a headless clone of your logged-in profile.

Perspective Coverage

5 publishers
Builder
Builder 30%
Operator
Operator 65%
Investor
Investor 5%

Reality

Evidence68
Adoption
Insufficient
Hype gap+10
Incentives40
Confidence70
security2 publishers

PamStealer now decrypts its macOS payload only through a live handshake with its C2 server

Jamf Threat Labs found a PamStealer build that completes a server key exchange before its macOS payload decrypts, so captured samples cannot be recovered offline. It also layers four persistence methods and a Swift stealer that harvests keychains and credentials from 13 browsers.

Reality

Evidence58
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence62