Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New PamStealer Malware Targets Mac Passwords

New PamStealer Malware Targets Mac Passwords

Posted on September 23, 2026 By CWS

A recent cybersecurity threat has emerged, targeting Mac users through a deceptive cryptocurrency wallet application. This fake app distributes the latest iteration of the PamStealer malware, posing significant risks to user security by capturing sensitive information, including passwords.

How the Attack Unfolds

The attack originates from a convincing website that prompts users to download a seemingly legitimate wallet application. Upon running the installer, an intricate process is initiated, capturing the Mac login password along with other private data. This new version of PamStealer, identified by researchers at Jamf Threat Labs, marks the third variant of this malware.

Unlike previous versions, this malware does not embed its malicious code directly within the initial download. Instead, it involves a dynamic interaction with an external server controlled by the attackers, complicating efforts to analyze the payload without server access.

Increased Sophistication of PamStealer

Insights from Jamf reveal that the current variant impersonates a multichain wallet, differing from previous campaigns that used a clipboard tool as a lure. The malware’s method of verifying passwords remains consistent, further complicating detection and analysis.

In controlled scenarios, researchers have observed the malware collecting and transmitting various data types. Although the exact number of victims and financial damages remain unclear, the potential for significant harm exists due to the combination of password theft and unauthorized access to browser data.

Technical Aspects and Prevention

The malicious site offers what appears to be a standard Mac download, which, in reality, contains a script with a misleading filename. The attack relies on users executing this script, which then decodes and runs additional scripts in the background.

The malware’s payload is embedded in a Mac component, circumventing typical notifications about new background processes. It maintains persistence by reactivating upon each login and can restore itself if partially removed.

To mitigate risks, Mac users are advised to verify any downloaded software and be cautious of unexpected scripts. Security protocols should be enforced to block similar activities, and compromised passwords should be reset from a secure device.

Indicators of compromise include various file paths, domains, and URLs associated with the malware’s operation. These indicators can assist in identifying affected systems and implementing appropriate defenses.

Overall, the PamStealer malware underscores the importance of vigilance and robust security practices to protect against evolving threats.

Cyber Security News Tags:crypto wallet, Cybersecurity, fake apps, Jamf Threat Labs, Mac security, Mac users, Malware, PamStealer, password theft, tech news

Post navigation

Previous Post: AWS Lambda Vulnerability Risks Unauthorized Cloud Access

Related Posts

Microsoft Defender AI to Uncover Plain Text Credentials Within Active Directory Microsoft Defender AI to Uncover Plain Text Credentials Within Active Directory Cyber Security News
Hackers Registered 18,000 Holiday-Themed Domains Targeting ‘Christmas,’ ‘Black Friday,’ and ‘Flash Sale’ Hackers Registered 18,000 Holiday-Themed Domains Targeting ‘Christmas,’ ‘Black Friday,’ and ‘Flash Sale’ Cyber Security News
Russian Calisto Hackers Target NATO Research Sectors with ClickFix Malicious Code Russian Calisto Hackers Target NATO Research Sectors with ClickFix Malicious Code Cyber Security News
Leading Serverless Security Solutions for 2026 Leading Serverless Security Solutions for 2026 Cyber Security News
North Korean Hackers Target South Korean Firms with Backdoor North Korean Hackers Target South Korean Firms with Backdoor Cyber Security News
Threat Actors Impersonate Fake Docusign Notifications To Steal Corporate Data Threat Actors Impersonate Fake Docusign Notifications To Steal Corporate Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New PamStealer Malware Targets Mac Passwords
  • AWS Lambda Vulnerability Risks Unauthorized Cloud Access
  • Armenian National Sentenced for Ryuk Ransomware Attacks
  • Unpatched Ubuntu Bug Allows Host-Root Container Escape
  • IBM Patches Critical FTM Vulnerabilities Affecting Payment Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New PamStealer Malware Targets Mac Passwords
  • AWS Lambda Vulnerability Risks Unauthorized Cloud Access
  • Armenian National Sentenced for Ryuk Ransomware Attacks
  • Unpatched Ubuntu Bug Allows Host-Root Container Escape
  • IBM Patches Critical FTM Vulnerabilities Affecting Payment Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark