Analysis of PamStealer’s Intel Mac Build Reveals Credential Theft and Dual Persistence

Summary
Analysis of an in-the-wild Intel x86_64 PamStealer sample finds credential and browser-data theft, crypto clipboard substitution, dual persistence, Ethereum-based C2 resolution, and anti-analysis checks. Attribution to Russian/CIS-linked cybercriminals is moderate-conf
Key points
- Telemetry identified an x86_64 PamStealer sample in late August 2026; it is one architecture slice of a fat binary that also includes an arm64 slice.
- A fake password prompt validates entered passwords against macOS PAM before sending credentials to the operators; the stealer also targets browser data and messaging databases.
- The malware monitors the clipboard and replaces copied cryptocurrency addresses with attacker-controlled addresses.
- It establishes login persistence through both SMAppService and a decrypted helper using legacy LSSharedFileList, so cleanup may need to check both mechanisms.
- For command and control, it retrieves encrypted configuration through Ethereum JSON-RPC calls to ERC-20 name() records, then sends encrypted data over HTTPS and can load native modules in-process.
- Anti-analysis measures include debugger and virtualization checks, environmental keying, and geofencing that excludes Russian and CIS locations; attribution to a financially motivated Russian/CIS-linked syndicate is moderate-confidence.
Article Details
- Attack Vectors
- Prior public analysis reported delivery through trojanized disk images impersonating Maccy; the analyzed Intel payload is a slice of a multi-architecture fat binary.
- A persistent password dialog captures user credentials and validates them through the local PAM authentication stack before exfiltration.
- A dialog using the genuine Finder icon falsely claims Finder lost access to protected data and directs the victim to grant Full Disk Access.
- The malware reads browser credential stores, messaging databases and targeted local files, subject to applicable access permissions.
- Clipboard monitoring replaces cryptocurrency payment addresses with attacker-controlled addresses.
- An operator-controlled task envelope directs the malware to download native modules and execute their entry points inside its own process.
- Defensive Notes
- Detection coverage should account for both Intel and Apple Silicon slices; architecture-specific hashes, code-signing hashes and byte signatures differ.
- Complete persistence removal requires checking both modern service registrations and legacy shared-file login lists. Removing only the modern registration can leave the helper intact on systems supporting legacy login lists.
- A hunt limited to ~/Library/LaunchAgents can miss this sample's persistence; researchers found no LaunchAgent plist path in the image.
- Full Disk Access requires the victim to enable the setting; researchers found no exploit that grants it automatically. Browser profile theft and clipboard substitution can proceed without that grant.
- Downloaded modules execute inside the existing malware process, so process-creation telemetry does not show a separate module launch.
- TLS inspection exposes an application/json POST containing a single data field, but the inner record remains encrypted.
- The configuration seed can be reconstructed statically because its initial value and all eight contributing constants are compiled into the binary.
- Researchers did not test whether the legacy helper successfully registers a login item on macOS 13 or later.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| SHA256 | 29ef90f7a64dda3d8bfdb873914a8f89b9c8b5acb5c1f829c94f8f766447f35c | SHA-256 of the decrypted 15,744-byte embedded login-item helper; the article states it is recompiled per build. |
| SHA256 | 9ac76794c37798420a052fbe21066f8e790ba4574f540543bb6e924a1e3d47d7 | SHA-256 of the analyzed PamStealer x86_64 Mach-O sample. |
| URL | hxxps[:]//flylikeabirdmyhoneypie[.]com/api/sync | Primary C2 endpoint receiving encrypted, base64-encoded records through application/json POST requests. |
MITRE ATT&CK
T1005 · Data from Local SystemThe sample reads messaging SQLite databases and targeted local files and stages copies for upload.T1027 · Obfuscated Files or InformationPamStealer XOR-encodes strings and encrypts configuration blobs with XChaCha20-Poly1305; its embedded helper is also encrypted.T1036.005 · Match Legitimate Resource Name or LocationThe article reports a com.apple.* identifier constructed from a word bank.T1041 · Exfiltration Over C2 ChannelEncrypted credential records and chunked file archives are uploaded through the malware's C2 transport.T1056.002 · GUI Input CaptureAn NSAlert containing an NSSecureTextField repeatedly requests the user's password until local PAM authentication succeeds.T1057 · Process DiscoveryNSRunningApplication and runningApplicationsWithBundleIdentifier: enumerate running applications.T1070.004 · File Deletionfile_unlink_selfdelete removes the sample from disk during its anti-analysis routine.T1071.001 · Web ProtocolsC2 transport uses HTTPS POST requests carrying application/json envelopes.T1082 · System Information DiscoveryThe sample collects the host serial number, processor brand, logical core count and display dimensions.T1102.001 · Dead Drop ResolverEthereum JSON-RPC eth_call requests read an ERC-20 name() field whose response is decrypted; researchers assess that it likely carries operator configuration.T1105 · Ingress Tool TransferThe module dispatcher downloads an operator-selected native module and loads it through dlopen inside the malware process.T1106 · Native APIThe sample uses native APIs including NSURLSession, posix_spawnp and dlopen for transport, helper execution and module loading.T1115 · Clipboard DataNSPasteboard changeCount is polled to inspect newly copied clipboard values.T1480.001 · Environmental KeyingEight anti-analysis checks contribute constants to the seed used to derive configuration decryption keys.T1497.001 · System ChecksIORegistry checks look for VMware, VirtualBox, Parallels and VirtIO device names before permitting execution.T1497.003 · Time Based ChecksThe article identifies nanosleep calls backed by ud2 instructions as part of the anti-analysis routine.T1547 · Boot or Logon Autostart ExecutionPersistence combines an SMAppService login item with a decrypted helper that registers a separate legacy LSSharedFileList login item.T1555.001 · KeychainBrowser collection includes Safe Storage keychain service-name lookups, although researchers could not confirm the mechanism used to unlock the entries.T1555.003 · Credentials from Web BrowsersThe malware targets Chromium-family and Gecko-family browser credential stores, including login and cookie databases.T1560.001 · Archive via UtilityCollected files are packed into a tar.gz archive before chunked upload.T1614.001 · System Language DiscoveryThe malware checks language locales and refuses execution for Belarusian, Armenian, Kyrgyz, Azerbaijani, Uzbek and Turkmen language environments.T1622 · Debugger EvasionThe sample checks sysctl P_TRACED and _dyld_debugger_notification and uses ud2 instructions that raise an exception when stepped over.T1657 · Financial TheftMatching cryptocurrency addresses in the clipboard are replaced with checksum-valid attacker-controlled addresses to redirect victim payments.
Malware
Products
ArcEdge Safe Storage, covering Chrome, Chromium, Edge, Brave, Opera and Opera GX, Vivaldi, Thorium and Arc.BraveSafe Storage, Chromium Safe Storage and Microsoft Edge Safe Storage, covering Chrome, Chromium, Edge, Brave, Opera and Opera GX, Vivaldi, Thorium and Arc.ChromiumHarvested targets include Chromium and Gecko browser vaults, messaging databases, and cryptocurrency transactions intercepted via real-time clipboard address replacement across major blockchain assets.Edgekeychain service names, with strings including Chrome Safe Storage, Chromium Safe Storage and Microsoft Edge Safe Storage, covering Chrome, Chromium, Edge, Brave, Opera and Opera GX, Vivaldi, Thorium and Arc.FloorpIt reaches Gecko-family browsers through profile paths for Firefox, LibreWolf, Waterfox, Zen and Floorp, and it enumerates Firefox add-ons through extensions.webextensions.uuids.Google ChromeIt looks up Chromium-family secrets by their keychain service names, with strings including Chrome Safe Storage, Chromium Safe Storage and Microsoft Edge Safe Storage, covering Chrome, Chromium, Edge, Brave, Opera andiMessageA WhatsApp query reads ZWAMESSAGE joined against ZWACHATSESSION, and the iMessage database path appears alongside it.LibreWolfIt reaches Gecko-family browsers through profile paths for Firefox, LibreWolf, Waterfox, Zen and Floorp, and it enumerates Firefox add-ons through extensions.webextensions.uuids.MaccyPrior public analysis observed PamStealer operating exclusively as an Apple Silicon (arm64) payload delivered via trojanized disk images impersonating the Maccy clipboard utility.macOSIn late August 2026, automated telemetry identified an in-the-wild sample of PamStealer , an emerging Rust-based macOS information stealer first documented by Jamf Threat Labs .Mozilla FirefoxIt reaches Gecko-family browsers through profile paths for Firefox, LibreWolf, Waterfox, Zen and Floorp, and it enumerates Firefox add-ons through extensions.webextensions.uuids.OperaStorage, Chromium Safe Storage and Microsoft Edge Safe Storage, covering Chrome, Chromium, Edge, Brave, Opera and Opera GX, Vivaldi, Thorium and Arc.Opera GXChromium Safe Storage and Microsoft Edge Safe Storage, covering Chrome, Chromium, Edge, Brave, Opera and Opera GX, Vivaldi, Thorium and Arc.Thoriumand Microsoft Edge Safe Storage, covering Chrome, Chromium, Edge, Brave, Opera and Opera GX, Vivaldi, Thorium and Arc.VivaldiStorage and Microsoft Edge Safe Storage, covering Chrome, Chromium, Edge, Brave, Opera and Opera GX, Vivaldi, Thorium and Arc.WaterfoxIt reaches Gecko-family browsers through profile paths for Firefox, LibreWolf, Waterfox, Zen and Floorp, and it enumerates Firefox add-ons through extensions.webextensions.uuids.WhatsAppA WhatsApp query reads ZWAMESSAGE joined against ZWACHATSESSION, and the iMessage database path appears alongside it.ZenIt reaches Gecko-family browsers through profile paths for Firefox, LibreWolf, Waterfox, Zen and Floorp, and it enumerates Firefox add-ons through extensions.webextensions.uuids.