Jamf Threat Labs found a PamStealer macOS variant that withholds its main payload until live X25519 key exchange and server-assisted decryption. This blocks offline analysis and relies on AppleScript, JXA and zsh loaders with multi-layer persistence. Hunt for JXA execution and anomalous C2 sessions. #PamStealer #MacOSMalware #ThreatIntel
https://cyberworldops.eu/en/pamstealer-makes-macos-payload-recovery-depend-on-its-command-server
#macosmalware
2 posts · Last used 13d
Discover how the new ClickLock macOS malware paralyzes systems and steals passwords. Learn vital defensive measures to protect your Apple computer today.
#ClickLock #macOSMalware #CyberSecurity #InfoSec
https://meterpreter.org/clicklock-macos-malware/?utm_source=mastodon&utm_medium=jetpack_social
You've seen all posts

