LIVE · cybersecurity feed
Live wire
security

PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords

Cybersecurity researchers have flagged a new macOS information stealer called PamStealer that employs a series of clever tricks to infect systems and siphon sensitive data. The stealer, discovered by Jamf Threat Labs, is distributed as a co

zeroday.news · 29d ago

A newly identified macOS malware, dubbed PamStealer, has been observed by cybersecurity researchers to be actively targeting Mac users by impersonating legitimate applications and exploiting system authentication mechanisms to steal login credentials. The threat, detailed by Jamf Threat Labs, utilizes a distribution method that involves tricking users into downloading malicious versions of popular applications.

PamStealer's initial infection vector relies on social engineering tactics. Threat actors are distributing malicious installers disguised as popular macOS applications. When a user downloads and executes one of these fake installers, it not only installs the intended application but also secretly deploys the PamStealer malware in the background. This approach leverages user trust in familiar software to gain a foothold on the system.

Once installed, PamStealer focuses on obtaining the user's login password, which is often protected by macOS's Keychain access control. The malware attempts to bypass these security measures by leveraging the operating system's own authentication processes. Specifically, PamStealer is designed to interact with the system's Pluggable Authentication Modules (PAM).

PAM is a framework that allows macOS to use different authentication methods. PamStealer exploits this by attempting to manipulate or query PAM to gain access to sensitive information, including user passwords. This method is particularly concerning as it targets a core security component of the operating system.

The ultimate goal of PamStealer is to exfiltrate the stolen login credentials. Once the malware successfully acquires the user's password, it transmits this sensitive data back to the attackers. This information can then be used for a variety of malicious purposes, such as unauthorized access to the compromised Mac, other online accounts, or for further targeted attacks.

The researchers highlighted that PamStealer's effectiveness stems from its combination of deceptive distribution and its exploitation of macOS's authentication system. By masquerading as legitimate software and then targeting PAM, the malware attempts to operate with a high degree of stealth and privilege.

While specific details on the full scope of PamStealer's capabilities and its prevalence are still emerging, the discovery underscores the ongoing threat landscape for macOS users. Information stealers remain a persistent category of malware, and attackers are continuously evolving their techniques to circumvent security defenses.

To mitigate the risks posed by threats like PamStealer, users are advised to exercise caution when downloading software. It is crucial to obtain applications only from trusted sources, such as the official App Store or the developers' official websites. Additionally, keeping macOS and all installed applications updated is a fundamental security practice, as updates often include patches for vulnerabilities that malware may attempt to exploit. Regularly reviewing security settings and being aware of potential phishing or social engineering attempts can also significantly enhance a user's defense posture.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.