Skip to content

other

PamStealer

An information-stealing malware family for macOS, named for its use of PAM-based checks to validate stolen system passwords.

Current clusters

security2 publishers

PamStealer now decrypts its macOS payload only through a live handshake with its C2 server

Jamf Threat Labs found a PamStealer build that completes a server key exchange before its macOS payload decrypts, so captured samples cannot be recovered offline. It also layers four persistence methods and a Swift stealer that harvests keychains and credentials from 13 browsers.

Reality

Evidence58
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence62