started · updated
PamStealer macOS malware adopts server-side decryption
Cybersecurity researchers have identified a new version of the PamStealer macOS malware that utilizes a server-side decryption chain to protect its main payload. Unlike previous variants that embedded key material directly in the JavaScript for Automation (JXA) source, this version requires a live key exchange with a command-and-control (C2) server to unwrap the payload. This design change makes static analysis significantly more difficult, as the payload cannot be recovered without the server’s cooperation.
The malware’s delivery method has also shifted. Victims are now lured via a fraudulent website for a non-existent cryptocurrency wallet service named ‘Wavel’. After downloading a malicious disk image, users are prompted to open a file that triggers the JXA dropper through Apple’s Script Editor. The process then hands off execution to a zsh script that runs in the background to carry out the infection.