Organisation
Jamf Threat Labs
Stories2
newest first
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
A new version of the PamStealer macOS malware uses server-side decryption and multi-layer persistence to evade detection.
1 outlet · one source so farNew macOS ClickLock malware forces users to reveal passwords by closing apps
The ClickLock macOS infostealer uses a 210-millisecond process-killing loop to coerce victims into providing their login password, enabling the exfiltration of Keychain data, browser credentials, and crypto wallets, while evading recent Apple mitigations for malicious Terminal paste activity.
1 outlet · one source so far