Back to all news
Security

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

The Hacker News·September 25, 2026·1 min read
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Researchers at Jamf Threat Labs flagged a new version of PamStealer macOS malware that adds live C2 payload decryption and multi-layer persistence. The updated variant still uses the same JXA dropper mechanism but modifies the lure and delivery method, making the main payload recoverable only via a server-side decryption chain.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store