As cited
Copy frozen at (site build).
threat intel
Newly discovered PamStealer isn't your typical macOS malware
Researchers discovered PamStealer, a previously unknown macOS malware distributed as a fake Maccy clipboard manager through a disk image containing malicious AppleScript. The malware uses a two-stage delivery mechanism and is written in Rust, leveraging macOS Pluggable Authentication Modules (PAM) interface to intercept and exfiltrate login credentials to attacker-controlled servers.
Why it matters: macOS users and security teams need to monitor for this malware variant, as its use of legitimate-looking applications and native system interfaces makes it difficult to detect; verify software sources and apply endpoint detection controls to identify credential theft attempts.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Newly discovered PamStealer isn't your typical macOS malware
Researchers discovered PamStealer, a previously unknown macOS malware distributed as a fake Maccy clipboard manager through a disk image containing malicious AppleScript. The malware uses a two-stage delivery mechanism and is written in Rust, leveraging macOS Pluggable Authentication Modules (PAM) interface to intercept and exfiltrate login credentials to attacker-controlled servers.
Why it matters: macOS users and security teams need to monitor for this malware variant, as its use of legitimate-looking applications and native system interfaces makes it difficult to detect; verify software sources and apply endpoint detection controls to identify credential theft attempts.
- Source published
- First seen by Cybersecurity Tracker