Jamf Threat Labs
jamf-threat-labs · B · active
https://www.jamf.com/blog/category/jamf-threat-labs/
macOS/Apple-platform threat-research lab. PRIMARY source for PamStealer macOS infostealer (2026-07-02), cited in entry 2026-07-04/pamstealer-macos-infostealer-pam-api-password-validation. Added as candidate 2026-07-04 — promote to active after 3 contributing runs. FETCH -> webfetch https://www.jamf.com/blog/category/jamf-threat-labs/ listing, then per-article webfetch for body (article pages resolve 200). | 2026-07-05 admiralty audit: B (HIGH->B) — original Apple-platform threat research. Keep candidate for now (single contribution) but promotion-ready: clean fetch history, strong niche relevance. | 2026-07-14 intel run: contributed CrashStealer macOS-infostealer entry (2nd contributing run after PamStealer 2026-07-04) — promotion-ready to active on next contribution. | 2026-07-26 weekly quality audit: promoted candidate → active on the documented lifecycle bar (cited by published entries from 4 distinct runs; the bar is 3). The promotion had never been executed because nothing counted contributing runs — the digest now emits sources.promotion_due (tools/run_summary.py).
Cited in 5 entries
Citation cadence
Citation days per ISO week (6 weeks of coverage span, total 5).
- A fake Zoom installer stages Overlord RAT through the first .NET macOS downloader Jamf has observed — PE-format DLLs bundled inside a Mach-O binary2026-08-07
- ClickFix was the week's universal crimeware delivery vector, and macOS gained a coercion playbook — five families this week converged on paste-into-terminal delivery, local password validation before theft, and decentralized dead-drop C22026-07-19
- CrashStealer — a native-C++ macOS infostealer using a notarized dropper and local dscl password validation to raid keychain, browsers and wallets2026-07-14
- The week's tradecraft converged on abusing trusted primitives — OAuth tokens, signed binaries, native auth APIs and legitimate SaaS2026-07-05
- Jamf Threat Labs documents "PamStealer": a macOS infostealer that validates the victim's password via the PAM API before exfiltrating it2026-07-04