← All stories
● Covered by 6 sources · 9 reportsMedium impact

PamStealer Malware Targets macOS for Credential Theft Using Apple's PAM

🔄 Updated 31d ago — new reporting from BleepingComputer
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • PamStealer malware targets macOS credential theft.
  • Malware uses Apple's PAM interface to validate passwords.
  • Distributed via disk image posing as Maccy clipboard manager.
  • Employs two-stage delivery with AppleScript and JXA.
  • Research by Jamf uncovers sophisticated tradecraft.

Overview of PamStealer Malware

PamStealer is a newly identified macOS malware threatening user credentials by impersonating legitimate applications and employing sophisticated evasion techniques. Researchers at Jamf discovered this malware exploiting Apple's Pluggable Authentication Modules (PAM) to validate and siphon passwords to an attacker's server.

PamStealer is named after its use of the PAM interface, and it poses a significant risk to macOS users by cleverly disguising its activities and components.

Delivery Method

The malware is distributed as a compiled AppleScript within a disk image, masquerading as Maccy, an open-source clipboard manager. The initial infection vector is a fake site resembling that of Maccy, designed to lure users.

Once executed, the AppleScript uses JavaScript for Automation (JXA) to stealthily download and stage the payload with Objective-C APIs, increasing its ability to evade detection.

Technical Details and Significance

The malware combines disk images and scripts to launch a second-stage Rust-based infostealing payload capable of credential and data theft from browsers and establishing data exfiltration channels.

By leveraging native macOS APIs and exploiting implicit user trust, PamStealer demonstrates the increasing sophistication and threat level of macOS-targeted malware.

Implications for macOS Security

PamStealer's discovery underscores potential vulnerabilities in macOS that malware can exploit by mimicking legitimate system components. Its ability to bypass quarantine flags and validate using the PAM framework highlights the need for increased vigilance and adaptation in security approaches.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~11 min · 9 stories · Aug 16

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The ClickLock malware for macOS forces users to input passwords by disabling processes and displaying fake dialogs. Its ability to steal sensitive information and install a backdoor poses significant security threats to affected systems.

A new malware, ClickLock Stealer, bypasses macOS protections using social engineering tactics to collect sensitive data from users. It targets over 100 individuals globally, exploiting the operating system’s design weaknesses and user permissions to exfiltrate information through a Telegram bot.

The ClickLock Stealer for macOS compromises user applications by initiating a loop that kills them every 210 milliseconds until the user inputs their login password. Discovered by Group-IB, the malware has targeted over 100 victims globally, predominantly in Europe, and allows attackers to extract sensitive information including browser credentials and cryptocurrency wallet data.

A new MacOS malware named 'CrashStealer' disguises itself as Apple's crash reporting tool, enabling data theft from user accounts and wallets. This malware, first identified by Jamf researchers, can bypass security measures due to its notarized status, posing a significant threat to Mac users.

A new malware targeting macOS, named 'CrashStealer', mimics Apple's crash reporting to extract user passwords. Discovered by Jamf, this malware gains access to personal data through a fraudulent crash report interface.

CrashStealer, a new macOS malware, disguises itself as Apple's crash-reporting tool to steal user credentials, keychain data, and cryptocurrency wallets. It employs tactics such as a fake password prompt and uses a notarized installer to bypass macOS security measures, posing a significant risk to users' sensitive information.

CrashStealer is a new macOS information stealer that uses a notarized dropper to bypass Gatekeeper checks. It harvests sensitive data from browsers and password managers, raising significant security concerns for macOS users.

Researchers identified PamStealer, a macOS malware using impersonation and PAM for credential theft. Its ability to execute successfully even with quarantine attributes poses a significant threat to macOS security.

Researchers discovered PamStealer, a novel macOS malware that stealthily collects user credentials. It employs unique delivery methods and a custom second stage, utilizing Apple's own mechanisms to evade detection and validation of passwords.