✦ For YouGeopoliticsTechFinanceHealthEnergySportsCulture◆ SN Last Week★ Saved

PamStealer macOS Malware Adds Live C2 Payload Decryption — SkimNews

By The Hacker News · Summarized & edited by · 2026-09-25
PamStealer macOS Malware Adds Live C2 Payload Decryption

Get the Tech newsletter

Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.

Why it matters: For macOS incident responders, this variant makes triage materially harder: without access to the live C2 server holding the private half of the X25519 exchange, the payload cannot be decrypted and traditional static sandboxing yields nothing. The expanded browser target list — specifically Arc, Zen, LibreWolf, and regional browsers like Yandex and Cốc Cốc — signals the operators are deliberately reaching users who've migrated off mainstream browsers for privacy reasons.

Share this story

Ask SkimNews
More tech → Read original →

Get the Tech newsletter

Curated tech stories, every morning. Free.

No spam. Unsubscribe anytime.