SOC Prime Bias: High

25 Sep 2026 08:15 UTC

PamStealer Shifts to Swift With a Server-Side Decryption Chain

Author Photo
SOC Prime Team linkedin icon Follow
PamStealer Shifts to Swift With a Server-Side Decryption Chain
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

A new PamStealer macOS infostealer variant introduces a major architectural shift from Rust to Swift. The updated malware relies on a server-side decryption chain powered by a custom utility called pkgunpack, requiring active C2 interaction to decrypt and execute the second-stage payload. It also uses layered persistence mechanisms while targeting browser credentials, Keychain data, and extensive system metadata.

Investigation

Jamf Threat Labs analyzed the new PamStealer variant after identifying it inside a fake cryptocurrency wallet installer named Wavel. The investigation uncovered a multi-stage execution chain beginning with a compiled JXA dropper, followed by a zsh-based stage that performs live key exchanges, and a Swift-based second stage responsible for credential theft and system fingerprinting.

Mitigation

Users should avoid downloading applications from unofficial sources, particularly software impersonating cryptocurrency wallets. Organizations should monitor for suspicious macOS background items and unauthorized changes to shell configuration files such as .zshrc. Endpoint security controls capable of detecting ad-hoc code signing, abnormal process reparenting, and unusual shell execution can further reduce exposure.

Response

When PamStealer activity is detected, isolate the affected macOS endpoint from the network to prevent further command-and-control communication and data exfiltration. Perform forensic analysis to determine the scope of credential theft, with particular attention to browser data and the macOS Keychain. Review system logs for unauthorized LaunchAgent creation, suspicious background items, and unexpected shell activity.

Attack Flow

We are still updating this part.

Detections

Forced Code Signing of Modified Application Bundle (via cmdline)

SOC Prime Team
24 Sep 2026

MacOS Archive Utility Pointing To Suspicious Directory (via cmdline)

SOC Prime Team
24 Sep 2026

Suspicious Use of Ditto for File Archiving and Exfiltration on macOS (via process_creation)

SOC Prime Team
24 Sep 2026

Suspicious Curl Execution Attempt [MacOS] (via cmdline)

SOC Prime Team
24 Sep 2026

Archive Was Created In MacOS Temporary Folder (via file_event)

SOC Prime Team
24 Sep 2026

Browser Helper Processes Termination for Credential Unlocking [Windows Process Creation]

SOC Prime AI Rules
24 Sep 2026

Detect xattr and codesign Usage for Bypass Techniques in PamStealer Variant [Linux File Event]

SOC Prime AI Rules
24 Sep 2026

PamStealer JXA Script Execution via Zsh [Linux Process Creation]

SOC Prime AI Rules
24 Sep 2026

Simulation Execution

  • Attack Narrative & Commands: The attacker seeks to deploy a payload that avoids disk detection. To achieve this, they use a command that decodes a Base64 encoded string and pipes it directly into a zsh subshell using the -s flag. To prevent an investigator from easily linking the malicious process to the original shell session, the attacker wraps the payload in a function named daemon_function, executes it in the background using &, and immediately exits the current shell to break the process tree linkage.

  • Regression Test Script:

    #!/bin/bash
    # Simulation of PamStealer JXA execution via zsh
    
    # Define the "malicious" payload as a function name and a command
    # The payload is piped to zsh -s to mimic the TTP
    PAYLOAD="daemon_function() { echo '[!] MALICIOUS PAYLOAD EXECUTED'; }; daemon_function & ; exit 0"
    
    # Execute the payload exactly as the detection rule expects
    echo "$PAYLOAD" | zsh -s
  • Cleanup Commands:

    # Cleanup is minimal as the command is piped and does not create persistent files.
    # We only need to ensure no background processes from the simulation are still running.
    pkill -f "daemon_function"