2026-07-04NOTABLEPamStealer impersonates the Maccy clipboard app and confirms a stolen macOS password through pam_authenticate before sending it
PamStealer
tool · tool:pamstealer single-source
PamStealer, two-stage macOS infostealer impersonating the Maccy clipboard manager; validates harvested login passwords via the macOS PAM API before exfiltration (Jamf Threat Labs)
Coverage
1
first 2026-07-04 → last 2026-07-04
Latest activity
2026-07-04
PamStealer impersonates the Maccy clipboard app and confirms a stolen macOS password through pam_authenticate…
Peak priority
notable
1 notable
Targets
·
no sector or region stated
Sources cited
2
2 hosts
Action items (3)
Do-now tasks recorded on the entries about PamStealer, newest first. Check the date before acting on an older one.
- Enforce Gatekeeper and notarization policy so unsigned or ad-hoc-signed applications launched from a mounted disk image cannot run; block AppleScript execution from quarantined/mounted images via an EDR script-control policy.2026-07-04PamStealer impersonates the Maccy clipboard app and…
- Alert on pam_authenticate invoked by any process other than loginwindow, sudo or su in the macOS Unified Log; legitimate password validation does not originate from a downloaded binary.2026-07-04PamStealer impersonates the Maccy clipboard app and…
- Restrict Full Disk Access grants by MDM policy and alert on new TCC.db entries for unrecognized bundle IDs, since the malware social-engineers the user into granting FDA.2026-07-04PamStealer impersonates the Maccy clipboard app and…
Defender insights
What each entry about PamStealer tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (7 across 7 tactics)
7 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ExecutionCommand and Scripting Interpreter: JavaScript
- PersistenceBoot or Logon Autostart Execution
- Privilege EscalationBoot or Logon Autostart Execution
- StealthMasquerading: Match Legitimate Resource Name or Location · Virtualization/Sandbox Evasion: System Checks
- Credential AccessCredentials from Password Stores: Keychain · Credentials from Password Stores: Credentials from Web Browsers
- DiscoveryVirtualization/Sandbox Evasion: System Checks
- CollectionClipboard Data
Execution TA0002
T1059.007Command and Scripting Interpreter: JavaScript×1
Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.
Evidence: 2026-07-04/pamstealer-macos-infostealer-pam-api-password-validation · ATT&CK page ↗
Persistence TA0003
T1547Boot or Logon Autostart Execution×1
Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.
Evidence: 2026-07-04/pamstealer-macos-infostealer-pam-api-password-validation · ATT&CK page ↗
Privilege Escalation TA0004
T1547Boot or Logon Autostart Execution×1
Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.
Evidence: 2026-07-04/pamstealer-macos-infostealer-pam-api-password-validation · ATT&CK page ↗
Stealth TA0005
T1036.005Masquerading: Match Legitimate Resource Name or Location×1
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
Evidence: 2026-07-04/pamstealer-macos-infostealer-pam-api-password-validation · ATT&CK page ↗
T1497.001Virtualization/Sandbox Evasion: System Checks×1
Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.
Evidence: 2026-07-04/pamstealer-macos-infostealer-pam-api-password-validation · ATT&CK page ↗
Credential Access TA0006
T1555.001Credentials from Password Stores: Keychain×1
Adversaries may acquire credentials from Keychain. Keychain (or Keychain Services) is the macOS credential management system that stores account names, passwords, private keys, certificates, sensitive application data, payment data, and secure notes. There are three types of Keychains: Login Keychain, System Keychain, and Local Items (iCloud) Keychain. The default Keychain is the Login Keychain, which stores user passwords and information. The System Keychain stores items accessed by the operating system, such as items shared among users on a host. The Local Items (iCloud) Keychain is used for items synced with Apple’s iCloud service.
Evidence: 2026-07-04/pamstealer-macos-infostealer-pam-api-password-validation · ATT&CK page ↗
T1555.003Credentials from Password Stores: Credentials from Web Browsers×1
Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.
Evidence: 2026-07-04/pamstealer-macos-infostealer-pam-api-password-validation · ATT&CK page ↗
Discovery TA0007
T1497.001Virtualization/Sandbox Evasion: System Checks×1
Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.
Evidence: 2026-07-04/pamstealer-macos-infostealer-pam-api-password-validation · ATT&CK page ↗
Collection TA0009
T1115Clipboard Data×1
Adversaries may collect data stored in the clipboard from users copying information within or between applications.
Evidence: 2026-07-04/pamstealer-macos-infostealer-pam-api-password-validation · ATT&CK page ↗
Entries about PamStealer (1)
Where this entity is cited
Source distribution
- jamf.com1 (50%)
- thehackernews.com1 (50%)