Skip to content
MagnaNet Network MagnaNet Network

  • Home
  • About Us
    • About Us
    • Advertising Policy
    • Cookie Policy
    • Affiliate Disclosure
    • Disclaimer
    • DMCA
    • Terms of Service
    • Privacy Policy
  • Contact Us
  • FAQ
  • Sitemap
MagnaNet Network
MagnaNet Network

PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords

Cahyo Dewo, July 5, 2026

The Anatomy of an Advanced macOS Infostealer

PamStealer’s attack chain is meticulously designed, unfolding in two distinct stages. The initial vector involves a compiled AppleScript (.scpt) file, which is distributed disguised within a disk image. This script serves as a downloader, tasked with fetching and preparing a secondary, more potent payload. The follow-on artifact is a robust, Rust-based infostealer, engineered for comprehensive credential theft, browser data collection, establishing persistence on the compromised system, and discreet data exfiltration to attacker-controlled infrastructure. This multi-stage approach, combining social engineering with advanced technical execution, exemplifies the evolving sophistication of threats targeting Apple’s ecosystem.

The initial point of compromise for PamStealer is a meticulously crafted lookalike website, "maccyapp[.]com," which mirrors the legitimate Maccy website, "maccy[.]app." Users, likely searching for the popular clipboard manager, are inadvertently led to this deceptive domain, where they download what they believe to be the genuine application. Instead, they receive the malicious disk image containing the "Maccy.scpt" AppleScript. This script, once launched, executes a self-contained JavaScript for Automation (JXA) downloader. This JXA component then leverages native Objective-C APIs to download and stage the Rust-based stealer payload, marking the transition to the second stage of the attack.

Bypassing Security: The Ingenuity of the AppleScript Dropper

One of the most notable aspects of PamStealer’s initial stage is its cunning method of execution designed to bypass common macOS security mechanisms. When the malicious AppleScript file is opened, particularly via the Script Editor, it presents a set of seemingly benign instructions. Users are prompted to run the script by using the "⌘ + R" keyboard shortcut or by clicking the "Run" button within the Script Editor interface. What makes this particularly insidious is that the malicious logic is hidden far below a substantial block of empty lines within the script. This clever obfuscation ensures that the user is unlikely to scroll down and discover the true intent of the script.

Furthermore, security researcher Thijs Xhaflaire from Jamf Threat Labs highlighted that this execution method is effective even when the file retains the com.apple.quarantine attribute. This attribute is a crucial component of macOS’s Gatekeeper security feature, designed to flag files downloaded from the internet and warn users before execution. By circumventing or at least neutralizing the impact of this attribute, PamStealer achieves a "quieter execution chain" than typically observed in commodity macOS stealers. This is a significant development, especially as Apple continues to enhance Gatekeeper and other system protections, demonstrating attackers’ persistent efforts to find new ways around them. The combination of an AppleScript dropper, a Rust-based second stage, and the unique PAM-based password validation workflow allows PamStealer to operate with a level of stealth and native integration that makes it particularly challenging to detect using traditional methods.

Sophisticated Evasion and Targeted Attacks

PamStealer incorporates advanced environment-aware features, a hallmark of more sophisticated malware. The AppleScript dropper is designed to proceed with its malicious activities only after successfully fingerprinting the host system to confirm it is running on Apple Silicon architecture. This fingerprinting process involves deriving a unique key based on several system attributes, including the CPU architecture, system locale, keyboard layout, and the device’s time zone. This derived key is then used to unlock an encrypted configuration file, which contains critical details such as the URL for the next-stage payload and its intended installation path.

On Intel-based Macs, the derived decryption key will inevitably differ, causing the decryption process to fail and the dropper to terminate. This selective targeting of Apple Silicon underscores the growing trend among threat actors to focus on newer architectures, which often present new challenges for security researchers and detection tools, and are rapidly expanding their market share.

PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords

Beyond hardware-specific targeting, PamStealer also employs geographical evasion tactics. The script is programmed to avoid execution within sandboxed or analysis environments, which are commonly used by security researchers to study malware safely. Moreover, it actively avoids systems where the time zone, system locale, and keyboard input resolve to countries located in Eastern Europe. Specifically, it sidesteps Russia, Belarus, Kazakhstan, Armenia, Azerbaijan, Kyrgyzstan, Moldova, Tajikistan, Uzbekistan, Turkmenistan, and Georgia. This geofencing strategy is a well-known tactic employed by some cybercriminal groups to avoid scrutiny or prosecution from law enforcement agencies within their home regions, adding another layer of complexity to its attribution and containment.

The Rust-Based Infostealer: Data Harvesting and Exfiltration

Once these stringent checks are passed, and the system is deemed a suitable target, the AppleScript reaches out to an external command-and-control (C2) server to download the final payload. This is a Mach-O binary written in Rust, a modern programming language increasingly favored by malware developers due to its performance, memory safety features, and the relative difficulty it presents for reverse engineering compared to languages like C++ or Python. The Rust binary masquerades as the legitimate macOS Finder application, a common tactic to blend into normal system processes and avoid suspicion.

This sophisticated infostealer is designed to harvest a comprehensive array of sensitive data from the compromised system. Its targets include:

  1. Web Browsers: It targets various web browsers to steal login credentials, browsing history, cookies, and autofill data. This information can be used for account takeover, identity theft, or further phishing campaigns.
  2. Cryptocurrency Wallet Extensions: A high-value target, as these extensions often contain private keys or seed phrases that grant access to digital assets. The theft of these can result in significant financial losses.
  3. iCloud Keychain: This macOS feature securely stores passwords for websites, apps, and Wi-Fi networks. Access to the iCloud Keychain can provide a wealth of credentials, potentially unlocking a user’s entire digital life.
  4. Clipboard Content: The stealer also captures real-time data from the clipboard, which can include sensitive information like copied passwords, financial details, or confidential documents that users temporarily store there.

After collecting this trove of data, the information is encrypted to prevent immediate inspection and then exfiltrated to the attacker-controlled infrastructure, specifically "avenger-sync[.]live," over an outbound HTTP request. This encrypted communication channel helps the attackers maintain stealth and evade network-based detections.

The Deceptive Password Validation Loop

One of PamStealer’s most cunning features is its method for stealing the victim’s system password. Beyond coercing the user into granting it full file system access, the stealer presents a native-looking password prompt, indistinguishable from a legitimate macOS system dialog. What sets this apart is its use of the macOS Pluggable Authentication Modules (PAM) API to validate the entered password locally. If the user inputs an incorrect password, the stealer does not simply fail; instead, it asks the user to re-enter the password, repeating this loop until the correct password is supplied. This iterative validation process ensures that the attackers only receive legitimate credentials, eliminating the noise of incorrect entries and making the process seem more authentic to the victim.

Once a valid password is successfully captured and verified, the stealer presents a second, counterfeit alert message: "Maccy is damaged and can’t be opened. You should move it to the Trash." This message is a near-perfect copy of a genuine Gatekeeper alert, designed to mislead the victim. Jamf Threat Labs explains that this is a deliberate decoy. By the time this message appears, the malicious payload has already completed its execution, captured the password, and established persistence on the system. The message serves merely to prompt the victim to discard the lure, making them believe the downloaded application was simply faulty, thereby reducing suspicion and the likelihood of immediate investigation into a security breach.

To ensure long-term access, the Rust binary also includes a small arm64 Mach-O component that impersonates macOS System Settings. This component is responsible for setting up persistence mechanisms, allowing the malware to survive system reboots and maintain its foothold on the compromised machine for continued data collection and control.

PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords

Reactions and Broader Implications

The discovery of PamStealer has prompted immediate action from the developer of the legitimate Maccy application, Alex Rodionov. Recognizing the severe threat posed by the impersonation, Rodionov swiftly updated the official Maccy website and its GitHub repository to include a prominent warning. The message explicitly urges users to exercise extreme caution and avoid fake websites mimicking the tool. "Beware of fake websites impersonating Maccy. Malicious sites (such as maccyapp[.]net and maccyapp[.]com) distribute malware disguised as Maccy. Maccy[.]app is the only official website," Rodionov stated, emphasizing the importance of downloading software only from verified, official sources. This proactive stance from the open-source community is crucial in combating such sophisticated phishing attempts.

Jamf Threat Labs concluded their analysis by highlighting that these behaviors collectively illustrate a significant evolution in commodity macOS stealers. The adoption of quieter execution chains, native implementations, and advanced evasion techniques reduces traditional detection opportunities while seamlessly integrating with standard macOS features. This trend represents a growing challenge for cybersecurity professionals and end-users alike.

The rise of PamStealer is not an isolated incident but rather indicative of a broader trend in the macOS threat landscape. Historically, macOS has enjoyed a reputation for being inherently more secure than Windows, leading to a perception of lower risk among its user base. However, as Apple’s market share continues to grow, particularly with the successful transition to Apple Silicon, macOS devices are becoming increasingly attractive targets for cybercriminals. The development of sophisticated, multi-stage malware like PamStealer, which employs native macOS technologies (AppleScript, JXA, Objective-C APIs, PAM) and modern programming languages (Rust), signals a maturity in macOS-focused offensive capabilities.

This incident also underscores the persistent threat of supply chain vulnerabilities and the impersonation of legitimate open-source projects. Open-source software, while offering transparency and community-driven development, can inadvertently become a vector for attacks when malicious actors create convincing fakes. Users are often less cautious when downloading open-source tools, assuming they are inherently safer, making them prime targets for such deception.

User Vigilance and Mitigation Strategies

In light of these evolving threats, user vigilance and robust cybersecurity practices are more critical than ever for macOS users. Several key mitigation strategies can help protect against threats like PamStealer:

  1. Verify Download Sources: Always download software directly from official developer websites or trusted app stores. Double-check URLs for subtle misspellings or alternative top-level domains. For open-source projects, refer to the official GitHub repository or project page for direct download links.
  2. Understand macOS Security Features: Familiarize yourself with Gatekeeper, which prevents the installation of unsigned or unverified applications. Be cautious of prompts asking to bypass these protections. While PamStealer attempts to circumvent com.apple.quarantine, understanding its purpose can still help identify suspicious behavior.
  3. Be Wary of Unexpected Prompts: Any unexpected system dialogs asking for your password, especially after downloading new software, should be treated with extreme suspicion. macOS typically does not repeatedly ask for your password in a loop if an initial entry is incorrect for a legitimate operation.
  4. Use Strong, Unique Passwords and MFA: Implement strong, unique passwords for all accounts, and enable multi-factor authentication (MFA) wherever possible. Even if a password is stolen, MFA can act as a critical secondary barrier against unauthorized access.
  5. Keep Software Updated: Regularly update your macOS operating system and all installed applications. Updates often include security patches that address newly discovered vulnerabilities.
  6. Employ Reputable Security Software: Consider using a reputable endpoint detection and response (EDR) solution or antivirus software for macOS. While no solution is foolproof, these tools can provide an additional layer of defense against known and emerging threats.
  7. Educate Yourself: Stay informed about the latest cybersecurity threats and common attack vectors. Understanding how malware operates can help users recognize and avoid deceptive tactics.

The PamStealer campaign serves as a stark reminder that no operating system is impervious to sophisticated attacks. As threat actors continue to innovate, combining technical prowess with social engineering, a proactive and informed approach to cybersecurity is paramount for all users, particularly those on the increasingly targeted macOS platform. The cybersecurity community, including researchers like Jamf Threat Labs, plays a vital role in uncovering these threats, but the ultimate defense lies in a combination of robust system protections and educated user behavior.

Cybersecurity & Digital Privacy checksCybercrimefakeHackingloginmaccypamstealerpasswordsPrivacySecuritysitesstealuses

Post navigation

Previous post
Next post

Recent Posts

Categories

  • AI & Machine Learning
  • Blockchain & Web3
  • Cloud Computing & Edge Tech
  • Cybersecurity & Digital Privacy
  • Data Center & Server Infrastructure
  • Digital Transformation & Strategy
  • Enterprise Software & DevOps
  • Global Telecom News
  • Internet of Things & Automation
  • Network Infrastructure & 5G
  • Semiconductors & Hardware
  • Space & Satellite Tech
©2026 MagnaNet Network | WordPress Theme by SuperbThemes