PamStealer Shifts to Swift With a Server-Side Decryption Chain
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
A new PamStealer macOS infostealer variant introduces a major architectural shift from Rust to Swift. The updated malware relies on a server-side decryption chain powered by a custom utility called pkgunpack, requiring active C2 interaction to decrypt and execute the second-stage payload. It also uses layered persistence mechanisms while targeting browser credentials, Keychain data, and extensive system metadata.
Investigation
Jamf Threat Labs analyzed the new PamStealer variant after identifying it inside a fake cryptocurrency wallet installer named Wavel. The investigation uncovered a multi-stage execution chain beginning with a compiled JXA dropper, followed by a zsh-based stage that performs live key exchanges, and a Swift-based second stage responsible for credential theft and system fingerprinting.
Mitigation
Users should avoid downloading applications from unofficial sources, particularly software impersonating cryptocurrency wallets. Organizations should monitor for suspicious macOS background items and unauthorized changes to shell configuration files such as .zshrc. Endpoint security controls capable of detecting ad-hoc code signing, abnormal process reparenting, and unusual shell execution can further reduce exposure.
Response
When PamStealer activity is detected, isolate the affected macOS endpoint from the network to prevent further command-and-control communication and data exfiltration. Perform forensic analysis to determine the scope of credential theft, with particular attention to browser data and the macOS Keychain. Review system logs for unauthorized LaunchAgent creation, suspicious background items, and unexpected shell activity.
Attack Flow
We are still updating this part.
Detections
Forced Code Signing of Modified Application Bundle (via cmdline)
MacOS Archive Utility Pointing To Suspicious Directory (via cmdline)
Suspicious Use of Ditto for File Archiving and Exfiltration on macOS (via process_creation)
Suspicious Curl Execution Attempt [MacOS] (via cmdline)
Archive Was Created In MacOS Temporary Folder (via file_event)
Browser Helper Processes Termination for Credential Unlocking [Windows Process Creation]
Detect xattr and codesign Usage for Bypass Techniques in PamStealer Variant [Linux File Event]
PamStealer JXA Script Execution via Zsh [Linux Process Creation]
Simulation Execution
-
Attack Narrative & Commands: The attacker seeks to deploy a payload that avoids disk detection. To achieve this, they use a command that decodes a Base64 encoded string and pipes it directly into a
zshsubshell using the-sflag. To prevent an investigator from easily linking the malicious process to the original shell session, the attacker wraps the payload in a function nameddaemon_function, executes it in the background using&, and immediately exits the current shell to break the process tree linkage. -
Regression Test Script:
#!/bin/bash # Simulation of PamStealer JXA execution via zsh # Define the "malicious" payload as a function name and a command # The payload is piped to zsh -s to mimic the TTP PAYLOAD="daemon_function() { echo '[!] MALICIOUS PAYLOAD EXECUTED'; }; daemon_function & ; exit 0" # Execute the payload exactly as the detection rule expects echo "$PAYLOAD" | zsh -s -
Cleanup Commands:
# Cleanup is minimal as the command is piped and does not create persistent files. # We only need to ensure no background processes from the simulation are still running. pkill -f "daemon_function"