New macOS malware PamStealer uses PAM to validate stolen data

Researchers have identified a new macOS infostealer called PamStealer that uses Pluggable Authentication Modules to validate stolen user passwords. The malware is distributed via a fake domain and targets Apple Silicon Macs while avoiding specific regions.
Why it matters
This highlights evolving sophisticated threats targeting macOS users and the increasing use of legitimate system APIs by attackers to evade detection.
X LinkedIn Reddit Facebook Share A previously undocumented macOS infostealer dubbed PamStealer validates victims' macOS passwords through the OS’s Pluggable Authentication Modules (PAM) before stealing them.
The article provides technical reporting on a cybersecurity threat based on research findings.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in