security2 publishers
PamStealer now decrypts its macOS payload only through a live handshake with its C2 server
Jamf Threat Labs found a PamStealer build that completes a server key exchange before its macOS payload decrypts, so captured samples cannot be recovered offline. It also layers four persistence methods and a Swift stealer that harvests keychains and credentials from 13 browsers.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence62