⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

September 25, 2026

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence Ravie LakshmananSep 25, 2026Malware / Social Engineering Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material directly in the JXA source, it now fetches a purpose-built decryption utility and completes a key exchange with the server before the payload can be unwrapped," security researcher Thijs Xhaflaire said in an analysis. "Without the server's cooperation, the payload cannot be recovered…