A new variant of the PamStealer malware has been identified, introducing technical advancements that force security teams to rethink how they analyze and defend against macOS threats.

Research from Jamf Threat Labs reveals the updated malware now requires a live connection to an attacker's command-and-control server to decrypt its core payload. This is a significant departure from prior versions, which contained the necessary decryption keys within the malware itself. As a result, the main malicious component remains inaccessible during standard offline analysis in sandboxes or by static tools, as it can only be unlocked remotely by the threat actor.

"This is a major analytical hurdle," the researchers stated in their disclosure, as reported by The Hacker News on September 29. The attack still leverages a JavaScript for Automation (JXA) dropper—a known macOS vector—but has changed its initial lure and delivery method to evade existing detections.

Beyond evasive encryption, the new PamStealer is built for persistence. The analysis uncovered multiple, layered mechanisms designed to maintain a long-term foothold on an infected machine. This moves its objective beyond simple data theft—such as stealing cryptocurrency wallets—to enabling sustained, stealthy data collection over time.

This level of sophistication was once the hallmark of advanced Windows malware. Its appearance on macOS underscores that the platform is now squarely in the crosshairs of sophisticated threat actors. The evolution shows macOS-specific attack vectors being combined with the persistence and evasion tactics matured in other ecosystems.

The security implications are clear. Relying solely on signature-based detection or filtering initial phishing lures is no longer adequate. Since the critical payload is encrypted until it receives remote instructions, defenders must shift their focus to monitoring behavior and network activity.

Effective defense now requires robust Endpoint Detection and Response (EDR) solutions that can spot anomalous process execution, suspicious script activity, and connections to newly contacted, untrusted domains. For IT teams, this highlights the necessity of a layered security strategy, where email security is merely the first step, followed by vigilant endpoint and network monitoring.

The discovery is a stark reminder that the macOS threat landscape is rapidly maturing. Organizations must secure their Mac fleets with the same seriousness as any other critical infrastructure, prioritizing real-time monitoring to detect malicious persistence and command-and-control communication.


安全研究人員識別出PamStealer惡意軟件的一個新變種,其引入的技術進展迫使安全團隊重新思考如何分析及防禦macOS威脅。

根據Jamf威脅實驗室的研究,更新後的惡意軟件現在需要與攻擊者的指揮及控制伺服器保持實時連接,才能解鎖其核心載荷。這與之前版本有顯著不同,過去版本在惡意軟件本身內置了必要的解密密鑰。因此,在沙盒或靜態分析工具進行的標準離線分析中,主要惡意組件將無法訪問,因為它只能由威脅行為者遠程解鎖。

研究人員在報告中指出:「這是一個重大的分析障礙。」如The Hacker News於9月29日報導所示。該攻擊仍然利用JavaScript for Automation(JXA)投放機制——這是一個已知的macOS攻擊媒介——但已更改其初始誘餌和傳遞方式以迴避現有偵測。

除了迴避性加密外,新的PamStealer專為持久化而設計。分析發現了多層機制,旨在長期佔據受感染機器。這使其目標超越了簡單的數據盜取——例如竊取加密貨幣錢包——而是實現長期、隱蔽的數據收集。

這種程度的複雜性曾是高級Windows惡意軟件的標誌。它在macOS上的出現凸顯了該平台現已成為複雜威脅行為者的明確目標。這種演進表明,macOS特定的攻擊媒介正與在其他生態系統中成熟的持久化和迴避策略相結合。

安全影響很明確。僅依賴基於特徵的偵測或過濾初始釣魚誘餌已不再足夠。由於關鍵載荷在收到遠程指令前一直保持加密狀態,防禦者必須將重點轉向監控行為和網絡活動。

有效的防禦現在需要強大的端點偵測與回應(EDR)解決方案,能夠識別異常進程執行、可疑腳本活動以及與新聯繫、不受信任的域建立的連接。對IT團隊而言,這凸顯了採取分層安全策略的必要性,其中電子郵件安全僅是第一步,其後是警覺的端點和網絡監控。

這一發現是一個鮮明的提醒:macOS威脅格局正在快速成熟。企業必須以對待任何其他關鍵基礎設施同樣的嚴肅態度來保護其Mac機群,優先實施實時監控以偵測惡意持久化和指揮及控制通信。

新聞來源 / Original News Source