PamStealer poses as an ordinary Mac utility
Jamf Threat Labs reports that PamStealer is a macOS infostealer disguised as the legitimate Maccy clipboard manager. It uses a fake AppleScript-based app to install a Rust payload that steals credentials, browser data, keychain-related information and clipboard contents while posing as system components such as Finder. The malware also shows fake macOS prompts to capture the user's password and request full disk access, making it harder to spot and giving attackers easier access to sensitive data.
What this means for your organisation
Macs are still treated in many organisations as something that does not quite need the same attention as Windows. This case shows why that does not hold. The attack succeeds because the fake prompts look exactly like the ones users approve every week anyway. Once the keychain and clipboard are emptied, the attacker holds credentials for everything that employee can reach, and none of it required a vulnerability.
Berigo recommends
- Bring Macs into the same device management and endpoint monitoring as your other clients.
- Restrict installation to approved applications and use central distribution rather than letting staff download their own.
- Teach staff that macOS never asks for their password in an arbitrary prompt in order to grant full disk access.
- Reset credentials for every service an affected user could reach, not just the local account.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch