HackerFeeds

CyberSecurity News

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

The Hacker News
· September 25, 2026

AI summary

Cybersecurity researchers have identified a new version of PamStealer macOS malware that features live command and control payload decryption. This updated version still uses the JavaScript for Automation dropper mechanism but has modified its lure and delivery method. The main payload can now only be recovered through a server-side decryption chain, adding an extra layer of complexity. The changes to the malware include modifications to how the payload key material is handled, according to Jamf Threat Labs. The malware also incorporates multi-layer persistence.

Read the full article at The Hacker Newsthehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.