{
  "id": 9790118,
  "title": "PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence",
  "url": "https://urgent.news/2026/09/25/pamstealer-macos-malware-adds-live-c2-payload-decryption-and-multi",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-25T13:18:06.000Z",
  "source": {
    "name": "The Hacker News",
    "slug": "the-hacker-news",
    "url": "https://thehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html"
  },
  "original_language": "en",
  "account": null,
  "summary": "Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. \"Where earlier variants embedded their payload key material",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}