Command-R instead of the "Installing" button. How One Hotle Runs Stealing Password On Mac

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
345
Reaction score
509
Deposit
0$
Malware for macOS is increasingly using the standard mechanisms of the system, and the new PamStealer styler masks the theft of the password for the installation of the manager of the Maccy buffer.

The malware is spread in the image of the disk and works in two stages. Inside is the AppleScript file, which, after double click, opens in the macOS script editor. The user is asked to immediately press Command-R, allegedly to start the installation. The combination executes hidden code directly in the editor, even if the file saves the attribute of com.apple.quarantine, with which macOS tags downloads from the Internet.

The first module runs a built-in bootloader written in JavaScript for Automation. The downloader does not access noticeable system commands like curl or zsh, but receives a second module through the state-of-the-art macOS interfaces. This approach leaves less than individual processes by which protective agents could recognize infection.

The second module is written on Rust and is designed for computers with Apple processors. The styler hides inside a fake app that pretends to be a Finder or Software Update, uses a system icon and works in the background. To read local databases, the malware uses the SQLite library built into it.


PamStealer then shows a window similar to a system request for permissions and asks for a password from an account. The malware checks the entered data through the PAM mechanism directly on the device. When an error, the request appears again, and after the correct password, the program reports that the application is damaged. Such a message should convince the victim that the installation just ended with a failure.

PamStealer also requests full access to the disk to collect more data, and accesses the public Ethereum nodes, although the purpose of these connections has not yet been established. A request for additional permits may appear with a delay of up to 40 minutes so that the user does not associate it with the launch of a fake installer.

Jamf experts are considering PamStealer as an example of a new generation of macOS stylers, which are less likely to launch external commands and more deeply use the system function.
 
Top Bottom