PamStealer Update Uses Server-Side Decryption and Layered Persistence on macOS

A new PamStealer variant requires a server-side decryption chain before its main payload can be recovered. Jamf Threat Labs found it still uses a JavaScript for Automation dropper but changes the lure and delivery method. Earlier versions had embedded key material, while this build keeps it server-side.
PamStealer’s latest variant changes how its payload is protected. According to Jamf Threat Labs, the macOS malware still relies on a JavaScript for Automation dropper, but the lure and delivery method have been updated. The main payload now requires a server-side decryption chain before it can be recovered.
Earlier PamStealer builds carried key material inside the sample. This version instead keeps that material on the server, and it also uses layered persistence on macOS. Those shifts distinguish the update from prior versions while leaving the core dropper technique in place.
The update could affect macOS users and security teams who investigate suspected infections. Because the payload depends on server-side decryption, defenders may have less ability to analyze a sample in isolation, potentially slowing detection and response. Organizations relying on endpoint protections and threat intelligence may need to adjust monitoring for this delivery pattern. The broader impact may remain limited unless the variant spreads widely, but it highlights how macOS malware can evolve to complicate investigation.