PamStealer macOS stealer adds live C2 decryption and multi-layer persistence
Malware Activity
Summary
Hide ▲
Show ▼
The PamStealer macOS stealer now uses a server-side decryption chain for its payload, making static recovery impossible without live C2 cooperation. The latest build also swaps in a fake wavel[.]app wallet lure and a Wavel.dmg download to start the infection. It then uses a JXA dropper and /bin/zsh stage to install multi-layer persistence and keep the repair logic alive across logins and Git activity. The final stealer targets passwords, keychain items, browser credentials, system metadata, and user files on macOS.
Related Happenings
MacSync macOS infostealer with iCloud calendar payload delivery
Malware Activity
H score29
First: 24.09.2026 23:53
Last: 24.09.2026 23:53
Sources 1
About this happening:
MacSync now uses public iCloud calendar events to deliver fresh payloads on macOS, expanding its infection chain and increasing the risk of credential theft and re...
MacSync macOS infostealer with iCloud calendar payload delivery
Malware ActivityAbout this happening: MacSync now uses public iCloud calendar events to deliver fresh payloads on macOS, expanding its infection chain and increasing the risk of credential theft and re...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware Activity
H score16
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware ActivityAbout this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
Go-based macOS stealer with DRAIN wallet-draining routine
Malware Activity
H score29
First: 07.08.2026 21:29
Last: 07.08.2026 21:29
Sources 1
About this happening:
A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also...
Go-based macOS stealer with DRAIN wallet-draining routine
Malware ActivityAbout this happening: A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also...
ClickFix Go-based macOS infostealer and crypto drainer
Malware Activity
H score29
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
About this happening:
A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
ClickFix Go-based macOS infostealer and crypto drainer
Malware ActivityAbout this happening: A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
ClickFix macOS Terminal-command lure campaign
Campaign
H score42
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
About this happening:
The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix macOS Terminal-command lure campaign
CampaignAbout this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
Timeline
-
25.09.2026 16:18 2 articles · 3h ago
Jamf Threat Labs flags PamStealer variant with live C2 payload decryption
Initial DisclosureJamf Threat Labs describes a new PamStealer macOS variant that replaces embedded payload keys with a server-side decryption chain, uses the bogus wavel[.]app lure and Wavel.dmg disk image to start execution, and relies on a JXA dropper that launches /bin/zsh before downloading pkgunpack, performing an X25519 key exchange, and staging the payload. The same build also adds redundant persistence through LaunchAgent creation, a repair script, ~/.zshrc and Git hook abuse, while the final Swift stealer targets passwords, keychain items, browser credentials, host fingerprinting data, and user files on macOS.
Show sources
- PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence — thehackernews.com — 25.09.2026 16:18
- PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence — thehackernews.com — 25.09.2026 16:18