CyberSecurity News
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
AI summary
Cybersecurity researchers have identified a new version of PamStealer macOS malware that features live command and control payload decryption. This updated version still uses the JavaScript for Automation dropper mechanism but has modified its lure and delivery method. The main payload can now only be recovered through a server-side decryption chain, adding an extra layer of complexity. The changes to the malware include modifications to how the payload key material is handled, according to Jamf Threat Labs. The malware also incorporates multi-layer persistence.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

