malware
PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
High
Summary
PamStealer, a new macOS information stealer developed by Jamf Threat Labs, utilizes deceptive tactics like mimicking the Maccy clipboard manager and exploiting Pluggable Authentication Modules (PAM) to steal login credentials. The malware employs a two-stage approach, starting with a compiled AppleScript dropper and culminating in a Rust-based infostealer for data collection and exfiltration. This technique allows for quieter execution and evades traditional detection methods.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
