New PamStealer virus for macOS: how stealthy data theft works

New PamStealer virus for macOS:

Researchers at Jamf Threat Labs have discovered sophisticated malware targeting macOS users. Dubbed PamStealer, the program uses hidden mechanisms to steal credentials and other sensitive information, successfully bypassing standard system protections.

What is PamStealer

PamStealer is a highly specialized info stealer that uses unique tactics to secretly infect computers. Unlike mass threats, this emphasizes social engineering and the use of legitimate system interfaces to minimize detection by security software.

Infection occurs in two stages. First, a disk image that mimics the popular Maccy clipboard manager is distributed. The first step uses an AppleScript script that runs the main Mach-O file written in the Rust programming language.

Peculiarities of operation and methods of password theft

The key feature of PamStealer is the second stage user interaction mechanism. The virus displays a window that copies the MacOS system interface, asking for authorization to run the Maccy program. When the user enters a password, the application verifies it through the standard Pluggable Authentication Modules (PAM) mechanism.

Unlike its counterparts, PamStealer does not use calls to tools such as dscl, security or osascript, which are usually tracked by antivirus systems. If an incorrect password is entered, the window prompts for it until the winning end. After entering the correct data, the virus issues an installation error message, as if the file is corrupted – this is a psychological trick that makes the user forget about the incident.

What data does PamStealer steal

In addition to gaining access to an administrator’s or user’s password, the malware performs additional actions to steal digital assets:

  • Requesting elevated rights (full disk access) for the fake Maccy program.
  • Scanning the system for Ethereum cryptographic wallets and gaining control over them.

A successful PAM interception architecture makes the malicious process as silent as possible, minimizing suspicious activity visible to the operating system.


Don't miss interesting news

Subscribe to our channels and read announcements of high-tech news, tes

Leave a Reply

Your email address will not be published. Required fields are marked *





Articles & testsArticles

Oppo A6 Pro smartphone review: ambitious Oppo A6 Pro (CPH2799)

Creating new mid-range smartphones is no easy task. Manufacturers have to balance performance, camera capabilities, displays, and the overall cost impact of each component. How the new Oppo A6 Pro balances these factors is discussed in our review.


In-Ear headphones Active Noise Cancellation: how Oppo eliminate noise Oppo Enco Air5s

In-ear headphones remain one of the most popular form factors due to their lightweight design. However, this design is considered one of the most challenging to implement active noise cancellation (ANC). We’ll explain how Oppo solved this problem.


NewsNews
| 10.08
Xbox is now available on Hisense TVs without a game console

Microsoft has launched the Xbox app for Hisense TVs running VIDAA OS, enabling cloud gaming without the need for a console.

| 07.08
Xiaomi ends the era of “top value for money”: prices have risen again

Xiaomi has revised its smartphone pricing in China for the second time this year. Most models have seen an increase of approximately 300 yuan.