Jamf Threat Labs has discovered a new Rust-based macOS infostealer called PamStealer that disguises itself as the Maccy clipboard manager to harvest user passwords and sensitive system data.
Key Points
- PamStealer uses a malicious AppleScript file to validate user passwords via macOS Pluggable Authentication Modules before stealing credentials.
- The malware targets Apple Silicon Macs and disguises its second-stage payload as legitimate system processes like Finder or Software Update.
- Attackers are distributing the malware through lookalike websites and sponsored advertisements on social media platforms like X.
- Once installed, the infostealer attempts to gain Full Disk Access to compromise browser data, Keychain information, and encrypted backups.
- Jamf Threat Labs also identified a separate campaign using X advertisements to distribute the Atomic Stealer variant via a site called dynamicmacisland.com.