💻
💻 Technology

PamStealer: new macOS malware steals login passwords using Apple's PAM interface

Researchers have discovered PamStealer, a previously unknown piece of macOS malware written in Rust. It exploits macOS's built-in Pluggable Authentication Modules (PAM) interface to validate and steal the victim's login password, sending it to an attacker-controlled server. The malware is delivered in two stages, with the first disguised as the Maccy clipboard manager and compiled as AppleScript to evade detection.

Comments

No comments yet