
highMalware
New PamStealer macOS Malware Variant Introduces Server-Side Decryption and Multi-Layer Persistence
Researchers from Jamf Threat Labs have identified a new variant of the PamStealer macOS malware that implements a server-side decryption chain for its main payload. The malware continues to rely on JavaScript for Automation (JXA) droppers but modifies lure and delivery methods. The decrypted payload enables live command-and-control communication and establishes multi-layer persistence on infected systems. No official patch is available; users are advised to avoid executing unknown scripts from untrusted sources.
The Hacker News1 min read