New macOS malware PamStealer uses PAM to validate stolen data
A previously undocumented macOS infostealer dubbed PamStealer validates victims' macOS passwords through the OS’s Pluggable Authentication Modules (PAM) before stealing them. Jamf Threat Labs researchers, who analyzed a two-stage attack chain combining AppleScript, JavaScript for Automation (JXA), and a Rust payload, report that attackers distribute PamStealer through the fake domain maccyapp[.]com, which impersonates the legitimate …
The post New macOS malware PamStealer uses PAM to validate stolen data appeared first on CyberInsider.
评论
?
参与讨论