A newly discovered variant of PamStealer malware adds live command-and-control (C2) payload decryption, making detection and analysis harder for security teams protecting macOS systems.

Researchers at Jamf Threat Labs identified the updated malware strain, which retains the same JavaScript for Automation (JXA) dropper but implements a critical change. Instead of embedding payload encryption keys locally, the malware now forces decryption through a server-side chain controlled by attackers. This architecture means the actual payload remains encrypted until the C2 server provides decryption instructions, preventing offline analysis and evading signature-based detection.

PamStealer targets macOS users and functions as an information stealer designed to exfiltrate passwords, browser data, and system credentials. The malware family first surfaced in late 2023 and has continuously evolved to bypass security controls. The JXA delivery mechanism remains popular because Apple's automation framework allows script execution with minimal user friction.

The multi-layer persistence approach in this variant ensures PamStealer survives system restarts. Researchers did not detail the specific persistence methods in available reporting, but typical macOS malware employs LaunchAgents, cron jobs, or login hooks to maintain execution across reboots. This layered strategy forces security teams to identify and remove multiple infection points to fully remediate compromised systems.

The shift to live C2 decryption represents a maturation in PamStealer's operational capabilities. Attackers gain three advantages from this approach. First, they can rotate decryption keys without recompiling malware samples, making each infection unique and harder to fingerprint. Second, defenders cannot recover or analyze the actual payload without compromising the C2 infrastructure. Third, network-based detection becomes less effective because the meaningful payload traffic stays encrypted with keys held server-side.

Organizations running macOS face real risk from this variant. Infection chains typically begin with phishing emails or trojanized downloads disguised as legitimate software. Once executed, PamStealer quietly harvests credentials and browser session data, giving attackers access to email accounts, cloud services, and internal systems. The stolen credentials feed into larger attack campaigns, including lateral movement and data exfiltration.

The lure modifications mentioned by Jamf Labs suggest attackers are testing new social engineering angles. Delivery method changes indicate they may use alternative channels beyond traditional phishing, possibly including supply chain compromises or malvertising.

Defenders should treat this as a priority. Detection requires behavioral monitoring rather than signature matching, since payloads encrypt dynamically. macOS security teams should monitor for unusual JXA script execution, suspicious network connections to unfamiliar C2 servers, and abnormal credential access patterns. Endpoint Detection and Response (EDR) tools with behavioral analysis capabilities offer better protection than traditional antivirus products.

User education remains essential. Staff should scrutinize unexpected emails, avoid downloading software from non-official sources, and grant execution permissions cautiously. Organizations should enforce code signing requirements and disable unsigned script execution where business operations allow.

Jamf's disclosure helps the security community track PamStealer evolution. As the malware continues advancing, defensive strategies must shift from reactive signature detection toward proactive behavioral containment and credential protection.