Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators PamStealer: a Rust-based macOS infostealer that validates credentials through PAM

https://api.live-updates.online/v2

TLP:CLEAR
Active

URL

Description

PamStealer is a two-stage macOS infostealer distributed as a compiled AppleScript impersonating Maccy, a legitimate clipboard manager, hosted on a fake domain. The first stage uses JavaScript for Automation with Objective-C APIs to download payloads while avoiding shell commands. The second stage is a Rust-based Mach-O binary that validates stolen credentials through PAM before harvesting, reads browser databases directly using bundled SQLite, captures clipboard contents repeatedly via pbpaste, and exfiltrates encrypted data using ChaCha20-Poly1305. It establishes persistence through both modern and legacy login item APIs, masquerades as Finder or System Settings, and tricks victims into granting Full Disk Access through counterfeit alerts. The stealer contacts Ethereum RPC endpoints and employs region-based exclusions targeting Apple silicon systems while avoiding Commonwealth of Independent States countries.

Sightings (0)

No sightings recorded yet

Details

Name / Label
PamStealer: a Rust-based macOS infostealer that validates credentials through PAM
Pattern Type
STIX
Confidence
75%
Valid From
Jul 5, 2026 00:57
Total Sightings
0
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of https://api.live-updates.online/v2

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.