Dettaglio notizia

Data 03/07/2026
Titolo PamStealer macOS Infostealer Uses Fake Maccy Apps and PAM Password Validation
Contesto Researchers have identified PamStealer, a previously unseen macOS malware family distributed through fake websites impersonating the legitimate Maccy clipboard manager. The infection begins with a trojanized disk image and a compiled AppleScript lure that tells users to press Command-R in Script Editor, a step that executes malicious code while sidestepping macOS com.apple.quarantine protections. The malware then deploys a Rust-based second stage that downloads additional payloads, steals browser data, clipboard contents, iCloud Keychain information, and login credentials, and sends the data to attacker-controlled infrastructure over encrypted command-and-control channels.

PamStealer stands out for validating stolen passwords locally through macOS Pluggable Authentication Modules (PAM), repeatedly prompting victims until the correct password is entered before exfiltration. Researchers said the malware is environment-aware, targets Apple Silicon systems, avoids analysis environments, and excludes devices tied to several Eastern European locales and time zones. It also delays Full Disk Access prompts, establishes persistence, and hides app bundles by impersonating Finder or Software Update components, while displaying decoy error messages to make victims think the fake application simply failed to launch.
Fonte https://mallory.ai/stories/019f2474-8b2b-78be-bc1e-79ba465501e1
Discussione? Parliamone sul Forum