Posted in

New PamStealer Malware Uses Server-Side Encryption to Target Mac Users

Cybersecurity researchers have identified a new version of PamStealer, a macOS information-stealing malware that uses a server-side decryption mechanism to make its main payload significantly harder to recover and analyze.

According to Jamf Threat Labs, the latest PamStealer campaign continues to use a JavaScript for Automation (JXA) dropper, but changes both the delivery method and the way the final payload is decrypted.

Earlier versions contained the necessary payload key material directly within the JXA source code. The new variant instead downloads a dedicated decryption utility and performs a cryptographic key exchange with the attacker’s server before the encrypted payload can be unlocked.

“Where earlier variants embedded their payload key material directly in the JXA source, it now fetches a purpose-built decryption utility and completes a key exchange with the server before the payload can be unwrapped,” Jamf Threat Labs researcher Thijs Xhaflaire said.

Without cooperation from the server, researchers cannot simply recover the final payload through static analysis.

Fake Wavel Cryptocurrency Wallet Used as a Lure

The latest PamStealer campaign also uses a new decoy.

Earlier variants observed in July and August 2026 impersonated legitimate applications and websites associated with Maccy, Scoppr and Nancy Clipboard.

The new campaign instead uses a fake website at wavel[.]app, which advertises a cryptocurrency wallet service called Wavel.

The service does not appear to be legitimate.

Visitors are presented with a “Download for macOS” button. Clicking it downloads a disk image called Wavel.dmg.

The disk image contains a compiled AppleScript file. Opening the file launches Apple’s built-in Script Editor, which displays instructions designed to persuade the victim to execute the malicious JXA-based dropper.

JXA Dropper Has Been Simplified

Previous PamStealer variants placed much of their malicious functionality directly inside the JXA source.

Those versions used RC4 to decrypt an embedded payload and relied on JXA’s Objective-C bridge to interact with macOS frameworks such as Foundation and NSData.

The latest Wavel variant takes a different approach.

The JXA layer now primarily acts as a carrier. When Script Editor executes the file, it decodes a Base64-encoded string and sends the resulting data to:

/bin/zsh -s

The Zsh process then reads the decoded bytes from standard input and executes them.

The JXA process terminates, while the Zsh-based dropper continues running in the background.

This separation allows the attackers to move much of the infection logic outside the JXA layer.

Server-Side Decryption Protects the Final Payload

The decoded Zsh script carries out several stages of the infection.

It:

  • Downloads and executes a decryption utility called pkgunpack.
  • Retrieves the utility from wavel.apple03cloudstore[.]com.
  • Performs an X25519 key exchange with the attacker’s server.
  • Uses the resulting key material to decrypt and stage the final payload.
  • Attempts to suppress macOS notifications associated with newly added background login items.
  • Establishes multiple persistence mechanisms.
  • Collects and uploads files from the staging directory.

The most significant change is the use of a live cryptographic exchange before the final payload can be decrypted.

The attacker’s server holds the private key required to complete the exchange. As a result, the Data Encryption Key (DEK) needed to decrypt the payload cannot be recovered without access to the server.

The malware also generates a new ephemeral key pair for every execution.

That means a previously captured DEK cannot simply be reused to decrypt another copy of the payload.

Live C2 Connection Makes Static Analysis Harder

The new design creates an important obstacle for malware researchers.

In previous versions, analysts could potentially extract the necessary key material from the malicious JXA source and use it to recover the embedded payload.

With the new implementation, the encrypted payload depends on communication with the attacker’s command-and-control infrastructure.

Without that server-side cooperation, the encrypted second stage is effectively inaccessible through static analysis alone.

Jamf researchers said this makes the operation more dependent on the availability of the attacker’s infrastructure while simultaneously making the malware considerably harder to analyze offline.

PamStealer Adds Multiple Persistence Mechanisms

The latest variant also introduces several ways to maintain access to an infected Mac.

One mechanism uses a LaunchAgent, a macOS feature commonly used to automatically start applications or scripts for a user.

The malware also installs a repair Zsh script that can restore both the payload bundle and LaunchAgent if they are removed.

Another persistence mechanism involves modifying the user’s:

~/.zshrc

The malware adds a shell hook that triggers the repair script whenever the victim starts a new interactive Zsh session.

This gives the attacker multiple opportunities to restore the malware if one component is deleted.

Git Hooks Provide Another Persistence Path

Researchers also discovered a more unusual persistence technique involving Git hooks.

The repair script is copied into:

~/Library/Application Support/System/.githooks/

Specifically, it is placed in the post-checkout and pre-commit hook locations.

PamStealer then modifies the global Git configuration using:

git config --global core.hooksPath

This causes Git to use the attacker’s custom hooks directory.

As a result, Git operations such as a checkout or commit can silently trigger the repair script.

This provides another mechanism for restoring the malware on systems where Git is regularly used.

New PamStealer Payload Written in Swift

The final-stage stealer has also undergone a technical change.

Earlier versions were written in Rust, while the new variant is implemented in Swift.

Despite the change in programming language, the malware’s objectives remain largely the same: steal credentials, collect sensitive files, gather system information and establish continued access to the compromised Mac.

The stealer can perform several types of information theft.

Mac Password Theft

PamStealer can display a fake crash-style dialog designed to trick the victim into entering their system password.

The malware then uses a PAM-based validation mechanism to determine whether the supplied credentials are valid.

Keychain Data

The malware can enumerate and retrieve items stored in the macOS Keychain, potentially exposing saved credentials and other sensitive information.

Browser Credentials

PamStealer targets credentials stored by a broad range of Chromium- and Firefox-based browsers.

The observed target list includes:

  • Google Chrome
  • Microsoft Edge
  • Mozilla Firefox
  • Brave
  • Vivaldi
  • Opera
  • Opera GX
  • Arc
  • Zen
  • Waterfox
  • LibreWolf
  • Yandex Browser
  • Cốc Cốc

Jamf noted that the inclusion of browsers such as Arc, Zen, and several regional and privacy-focused browsers expands the malware’s target list beyond what is commonly seen in commodity macOS information stealers.

PamStealer Collects User and System Data

Beyond passwords and browser credentials, the malware gathers information that can help attackers profile the victim and their environment.

It can collect:

  • System fingerprints
  • Hardware and operating-system information
  • User profile information
  • The user’s profile photo
  • Running processes
  • Installed applications
  • Shell history
  • .zsh_history
  • .zshrc
  • .bash_history
  • .gitconfig

These files can contain valuable information about commands executed by the user, development environments, credentials and other operational details.

PamStealer Shows a More Sophisticated Delivery Strategy

The latest PamStealer campaign represents a significant change in how the malware protects its payload.

Rather than placing all of the decryption material inside the initial dropper, the attackers have introduced a live X25519 key exchange that connects payload decryption to their server infrastructure.

This approach makes the malware harder to recover and analyze without access to the command-and-control server.

At the same time, the campaign combines several persistence techniques, including LaunchAgents, shell configuration changes and Git hooks.

“The inclusion of Arc, Zen and the less common regional and privacy-focused browsers extends the target list noticeably beyond what is typical in commodity macOS stealers,” Xhaflaire said.

The new PamStealer variant therefore combines a deceptive cryptocurrency-wallet lure, layered persistence, broad credential theft and server-controlled payload encryption.

Jamf’s analysis suggests the attackers have made a deliberate investment in the malware’s delivery infrastructure, shifting part of the decryption process away from the infected Mac and into their own server environment.

Leave a Reply

Your email address will not be published. Required fields are marked *