Cybersecurity researchers have identified a new variant of PamStealer, dubbed 'Wavel', which targets macOS users through a deceptive website masquerading as a cryptocurrency wallet service. This version represents a significant evolution in complexity, utilizing a server-side decryption chain that requires a live key exchange (X25519) with a command-and-control server to unwrap the main payload. This architectural change makes static analysis and payload recovery nearly impossible without an active C2 session.
The infection chain begins with a compiled AppleScript that executes a JavaScript for Automation (JXA) dropper, which then transitions to a background zsh script. This script implements redundant persistence mechanisms, including the hijacking of global Git hooks to ensure the malware re-activates during routine developer activities. The final payload, now written in Swift, focuses on stealing system passwords via fake crash dialogs, harvesting keychain items, and exfiltrating data from a wide range of web browsers.
Top comments (0)