PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Headline by Prism · from 1 report
A new version of the PamStealer macOS malware uses server-side decryption and multi-layer persistence to evade detection.
The Hacker NewsThe brief
Written by software from the 1 report below.
- The updated PamStealer malware lures victims to a fake cryptocurrency website to download a malicious disk image file.
- This malware now employs a live server-side key exchange, which prevents security researchers from decrypting the payload without an active command-and-control connection.
- It installs multiple layers of persistence, including a technique that triggers the malware through local Git repository actions.
- The stealer targets a wide range of browser credentials, system passwords, and user files to compromise the host.
What to watch next
- Future evolution of persistence techniques targeting Git hooks.
- Expanded targeting of niche and privacy-focused web browsers.
- Operational longevity of the Wavel-themed distribution infrastructure.
The points restate the reports; where one says why it matters, that is Prism's reading, not a reported fact.
Who said what
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Thijs Xhaflaire
security researcher
3 quotes · 1 outlet
“Where earlier variants embedded their payload key material directly in the JXA source, it now fetches a purpose-built decryption utility and completes a key exchange with the server before the payload can be unwrapped”
In the article
…recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. " Where earlier variants embedded their payload key material directly in the JXA source, it now fetches a purpose-built decryption utility and completes a key exchange with the server before the payload can be unwrapped ," security researcher Thijs Xhaflaire said in an analysis. "Without the server's cooperation, the payload cannot be recovered statically." A second major change is the choice of the decoy itself. While previous…
“In Maccy, Scoppr and Nancy, the JXA source performed RC4 decryption of an embedded payload, made Objective-C framework calls through JXA's bridge to Foundation and NSData, and managed the entire download and staging process”
In the article
…to the retrieval of a disk image file ("Wavel.dmg") that contains a compiled AppleScript file. Opening the file launches Apple's built-in Script Editor with instructions to trigger the execution of a JXA dropper. " In Maccy, Scoppr and Nancy, the JXA source performed RC4 decryption of an embedded payload, made Objective-C framework calls through JXA's bridge to Foundation and NSData, and managed the entire download and staging process ," Xhaflaire explained. "In Wavel, the JXA source contains none of that. The entire JXA layer is now a carrier. When Script Editor executes the file, it decodes the base64 string and pipes the result into /bin/zsh -s,…
Coverage
1 outlet
All filed from India
NamedUnited States · Apple · Wavel · Jamf Threat Labs · PamStealer · Thijs Xhaflaire
The 1 report is listed beside the record.
Corrections and versions
A correction says what was wrong and why. Every earlier headline and brief of this record is kept.
Something wrong?
Say what, and it arrives with this record's address filled in. A correction is welcome.
Ask this story
Answers cite the 1 report above, or say they can't.