New macOS malware PamStealer uses PAM to validate stolen data

A previously undocumented macOS infostealer dubbed PamStealer validates victims' macOS passwords through the OS’s Pluggable Authentication Modules (PAM) before stealing them. Jamf Threat Labs researchers, who analyzed a two-stage attack chain combining AppleScript, JavaScript for Automation (JXA), and a Rust payload, report that attackers distribute PamStealer through the fake domain maccyapp[.]com, which impersonates the legitimate …

The post New macOS malware PamStealer uses PAM to validate stolen data appeared first on CyberInsider.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论