HomeYoutubePamStealer: New Mac malware confirms passwords before "emptying" the system

PamStealer: New Mac malware confirms passwords before "emptying" the system

While macOS is still considered by many to be a highly secure operating system, cybercriminals are now developing more sophisticated techniques specifically targeting Mac. One of the latest threats is PamStealer, a new infostealer that, according to researchers at Jamf Threat Labs, introduces a particularly dangerous approach: it verifies that the password the victim types is valid before proceeding to steal personal data.

This feature significantly increases the value of stolen credentials, as perpetrators know from the very beginning that they have functional login details.

Disguise in a popular app

The PamStealer distribution campaign relies on social engineering . Attackers create a fake website that closely mimics the legitimate Maccy clipboard manager, tricking users into downloading a supposedly legitimate program.

See also: Apple working on Mac Studio M7 Ultra for 2028 with possible major upgrade

In fact, the file that is installed is a malicious AppleScript. Once executed, it performs initial checks on the system and retrieves a second payload, which has been developed in the Rust. From there, the malware is permanently installed on the system, ensuring that it will continue to run even after the computer is restarted.

PamStealer: New Mac malware confirms passwords before "emptying" the system

Targeted attacks instead of mass distribution

Another feature that makes PamStealer stand out is that it does not activate indiscriminately on every computer. Before performing its basic functions, it examines various macOS parameters, such as system characteristics, keyboard layout, and regional settings.

This behavior suggests that its creators are interested in specific targets rather than a generalized infection campaign, while also limiting the chances of the malware being detected by security researchers.

PamStealer: The innovation lies in the code verification

The element that most differentiates PamStealer from other infostealers is the credential collection process.

The malware displays a window that looks exactly like the authentic macOS authorization window, asking the user for the administrator password to supposedly make changes to the application.

See also: M5 Ultra Mac Studio to be released in 2026 with up to 768GB of RAM

However, it doesn't just store what the user types. Instead, it leverages Apple's legitimate PAM (Pluggable Authentication Modules ) system to verify that the password is actually correct . It doesn't break or bypass the operating system's authentication mechanism, but rather exploits its legitimate capabilities, offering attackers instantly verified credentials.

PamStealer macOS infostealer fake Maccy stealing PAM passwords

Extensive collection of personal data

Once verification is complete, the second stage of the malware begins collecting sensitive information. Its targets include cookies and browsing history, saved passwords, SQLite databases, clipboard contents, and data from cryptocurrency wallets.

Before being sent to the attackers' servers, all data is encrypted, making it difficult for both security experts to detect suspicious network traffic and analyze the attack.

At the same time, PamStealer attempts to gain "Full Disk Access" rights, even impersonating Finder, in order to gain access to even more of the user's files without additional restrictions.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Rust makes analysis difficult

The researchers point out that much of the second stage has been developed in Rust, a choice that is not accidental. This language makes difficult reverse engineering, as many critical strings and execution paths are only revealed during program execution and not in the final binary.

This trend has been observed more and more frequently in recent years, as several cybercriminal groups choose Rust to increase the complexity of their attacks and delay the development of detection tools.

See also: Steam: Mac game developers need to update

PamStealer: New Mac malware confirms passwords before "emptying" the system

What users should watch out for

The PamStealer case proves that modern threats are not necessarily based on unknown vulnerabilities, but on the abuse of legitimate functions of the operating system itself and, above all, on deceiving the user.

Protection starts with downloading applications only from trusted sources, thoroughly checking the address of each website before any installation, and treating any unexpected request for an administrator password with extreme caution. It is equally important to grant the “Full Disk Access” permission only when absolutely necessary and to applications from trusted developers. Finally, regularly updating macOS and security solutions remains one of the most effective ways to promptly detect and block known threats.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS