AUTO-UPDATED

Fake Mac Clipboard App Delivers New Password-Stealing Malware

Jamf Threat Labs has discovered a new Rust-based macOS infostealer called PamStealer that disguises itself as the Maccy clipboard manager to harvest user passwords and sensitive system data.

Key Points

  • PamStealer uses a malicious AppleScript file to validate user passwords via macOS Pluggable Authentication Modules before stealing credentials.
  • The malware targets Apple Silicon Macs and disguises its second-stage payload as legitimate system processes like Finder or Software Update.
  • Attackers are distributing the malware through lookalike websites and sponsored advertisements on social media platforms like X.
  • Once installed, the infostealer attempts to gain Full Disk Access to compromise browser data, Keychain information, and encrypted backups.
  • Jamf Threat Labs also identified a separate campaign using X advertisements to distribute the Atomic Stealer variant via a site called dynamicmacisland.com.

Why it Matters

This campaign highlights the growing sophistication of social engineering tactics that exploit user trust in sponsored advertisements and open-source software. By bypassing traditional security monitoring and abusing legitimate system prompts, these infostealers pose a significant risk to both individual privacy and corporate data security.
Decrypt Published by Jason Nelson
Read original