Jamf Threat Labs
jamf-threat-labs · B · candidate
https://www.jamf.com/blog/category/jamf-threat-labs/
macOS/Apple-platform threat-research lab. PRIMARY source for PamStealer macOS infostealer (2026-07-02), cited in entry 2026-07-04/pamstealer-macos-infostealer-pam-api-password-validation. Added as candidate 2026-07-04 — promote to active after 3 contributing runs. FETCH -> webfetch https://www.jamf.com/blog/category/jamf-threat-labs/ listing, then per-article webfetch for body (article pages resolve 200). | 2026-07-05 admiralty audit: B (HIGH->B) — original Apple-platform threat research. Keep candidate for now (single contribution) but promotion-ready: clean fetch history, strong niche relevance. | 2026-07-14 intel run: contributed CrashStealer macOS-infostealer entry (2nd contributing run after PamStealer 2026-07-04) — promotion-ready to active on next contribution.
Cited in 3 entries
Citation cadence
Citation days per ISO week (3 weeks of coverage span, total 3).
- CrashStealer — a native-C++ macOS infostealer using a notarized dropper and local dscl password validation to raid keychain, browsers and wallets2026-07-14
- The week's tradecraft converged on abusing trusted primitives — OAuth tokens, signed binaries, native auth APIs and legitimate SaaS2026-07-05
- Jamf Threat Labs documents "PamStealer": a macOS infostealer that validates the victim's password via the PAM API before exfiltrating it2026-07-04