logo

PamStealer Mimics Maccy Clipboard Manager Silently Harvests Data and Clipboard Contents

ID: db0a943d-30cb-5af4-940f-7b9dde2f591e

STIX ID: report--db0a943d-30cb-5af4-940f-7b9dde2f591e

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-07-04

Date Updated: 2026-07-04

Author: Abinaya

...
...

Jamf Threat Labs identified PamStealer, a macOS infostealer masquerading as the open-source clipboard manager “Maccy.” The attack uses a socially engineered disk image containing an AppleScript dropper that runs a JXA payload to fetch a Rust-based Mach-O second-stage binary. PamStealer collects clipboard data, extracts browser databases and Keychain secrets, prompts users for passwords (validated via PAM), attempts to obtain Full Disk Access, persists via login items and helper binaries, and exfiltrates encrypted data (ChaCha20-Poly1305) to C2 domains such as avenger-sync.live; the report includes multiple IOCs and behavioral TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.