news.mlab.sh
Back to the feed
malware

PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords

High
Image: The Hacker News
Summary

PamStealer, a new macOS information stealer developed by Jamf Threat Labs, utilizes deceptive tactics like mimicking the Maccy clipboard manager and exploiting Pluggable Authentication Modules (PAM) to steal login credentials. The malware employs a two-stage approach, starting with a compiled AppleScript dropper and culminating in a Rust-based infostealer for data collection and exfiltration. This technique allows for quieter execution and evades traditional detection methods.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.