Signal

MacOS infostealers evolve payload delivery and decryption

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-09-24 10:00 UTCUpdated 2026-09-25 22:07 UTC
rss
malwaremacosinfostealerpamstealermacsyncthreat_intelligence
Trend in the last 24h
Source links open
Source links and full evidence are open here. Pro adds archive history, compare-over-time, alerts, exports, and workflow. Business adds Feed API integrations and team usage.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.
3 top sources shown
Overview

Recent reporting points to continued evolution in macOS infostealer operations. PamStealer has added server-side payload decryption while retaining a JXA dropper, whereas MacSync has shifted toward binary delivery and Objective-C and Swift payload modules. The reports describe related defensive concerns but do not establish that the two families are connected.

Entities
Jamf Threat LabsKasperskyPamStealerMacSyncSergey Puzan
Why now
  • The reports describe newly observed or updated macOS malware activity in September 2026.
  • Multiple sources are flagging changes to delivery and payload mechanisms within the same 24-hour reporting window.
Why it matters
  • Server-side decryption can make PamStealer payload recovery dependent on its external delivery chain.
  • MacSync’s binary delivery and native-language modules represent a change from its earlier script-based approach.
Evidence assessment
Recurring claims
  • A new PamStealer variant uses a server-side decryption chain to recover its main payload and continues to use a JXA dropper.
  • MacSync has adopted binary payload delivery, with malicious modules written in Objective-C and Swift.
  • MacSync is described as a rapidly evolving macOS crypto and information stealer distributed under a malware-as-a-service model.
How sources frame it
  • The Hacker News: neutral
  • SC Media: neutral
  • Kaspersky: neutral
Three reports highlight evolving macOS infostealer delivery and payload techniques, while covering two distinct malware families.
All evidence
All evidence
New PamStealer variant uses server-side decryption for macOS malware
Scworld · scworld.com · 2026-09-25 22:07 UTC
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Thehackernews · thehackernews.com · 2026-09-25 13:18 UTC
MacSync under the microscope: new delivery methods and a new payload
Securelist · securelist.com · 2026-09-24 10:00 UTC
Show filters & breakdown
Evidence items loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 3