PamStealer: a Rust-based macOS infostealer that validates credentials through PAM
ID: 37462adb-b8c9-570d-89fa-b7486f5abe35
STIX ID: report--37462adb-b8c9-570d-89fa-b7486f5abe35
Feed Name: Jamf Blog
PamStealer is a macOS-focused infostealer delivered via a Script Editor (.scpt) JXA dropper that stages a Rust arm64 Mach-O. The dropper performs environment- and region-aware checks, ad-hoc signs and launches a staged bundle masquerading as Finder or Software Update; the second-stage steals browser credential databases, clipboard contents, and validated login passwords via a PAM-backed fake authorization prompt, attempts to coerce Full Disk Access via a counterfeit system dialog, persists through login item APIs (both modern and legacy) including an embedded helper, and exfiltrates data to an encrypted Cloudflare-fronted C2 (notably avenger-sync.live) using ChaCha20-Poly1305; analysis artifacts and caches provide actionable IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
