The lure: Wavel, a fake application installer
At a Glance
| Attribute | Details |
|---|---|
| Malware Family | PamStealer (internal project name: MacClient) |
| Threat Actor | Unknown cybercriminals (unconfirmed attribution) |
| Target Victims | macOS users, cryptocurrency investors, and software developers |
| Delivery Vector | Malicious disk image (DMG) hosting a fake Wavel crypto wallet app |
| Key Capabilities | ECIES key exchange, PAM credential validation, Keychain theft, browser extraction |
| Source | Jamf Threat Labs (supported by LOpsec research) |
Executive Summary
Jamf Threat Labs discovered an active attack campaign distributing the PamStealer macOS infostealer through deceptive cryptocurrency investment websites. Attackers rewrote the core payload from Rust into Swift while introducing dynamic server-side decryption routines. Additionally, the malware installs multiple self-healing persistence mechanisms to resist endpoint remediation attempts.
Delivery Tactics and Fake Crypto Wallet Lure
Threat actors distribute the malware through a website impersonating a legitimate cryptocurrency platform. The site offers a direct download for a multi-chain wallet application named Wavel. When users download the provided disk image, they receive a compiled AppleScript file. Because macOS hides file extensions by default, the script looks like a standard document.
When a victim opens the file, Script Editor loads an embedded JavaScript application. This script contains a large Base64 string that decodes into a shell command. The process immediately spawns a background shell script to handle subsequent tasks. Jamf Threat Labs highlighted this transition: “What distinguishes this variant from its earlier ones is not what it collects but how it is delivered.” Consequently, the parent process exits immediately to obscure visible execution traces.
Infection Chain Architecture
The background script downloads a specialized binary utility named pkgunpack to manage payload decryption. Rather than storing static encryption keys inside the script, the tool performs a live cryptographic key exchange. It sends an ephemeral public key to an external authentication server.
Server-Side Decryption and pkgunpack
The server responds with an encrypted Data Encryption Key blob. The local utility uses elliptic-curve algorithms to derive a shared secret and decrypt the payload. As Jamf researchers noted, “Without the server’s cooperation, the payload cannot be recovered statically.” Therefore, defenders cannot analyze the core payload without an active server session.
After decrypting the application bundle, the script renames the file to Finder.app inside the user support directory. It then applies an ad-hoc signature to bypass Gatekeeper execution controls without triggering user prompts.
Notification Suppression and Multi-Layer Persistence
Before establishing persistence, the script pauses system notification processes using operating system signals. It halts the background task management agent and the notification center. Consequently, macOS cannot alert the user when the installer registers a new login item. After registering a LaunchAgent that runs every 15 seconds, the script terminates the paused processes.
Furthermore, the installer deploys three redundant repair mechanisms to ensure long-term persistence. It places a local recovery script that restores missing files from a hidden backup archive. In addition, the installer modifies the user shell configuration file to execute this repair script during new sessions. The installer also alters global Git hooks. As a result, executing common Git commands automatically triggers the repair routine.
Command-and-Control and Data Exfiltration Behavior
The core executable represents a complete rewrite from Rust into the Swift programming language. The malware contains internal references to a project called MacClient. It displays deceptive user interface windows to capture administrator passwords. The report states, “The binary includes a full AppKit-based decoy user interface implemented in the AuthPromptWindow class.”
Swift-Based Infostealer and PAM Password Theft
The tool prompts the user for their system password and validates it through the Pluggable Authentication Modules framework. Next, the malware extracts login keychains and modifies access control lists. It also terminates background helper processes across seventeen web browsers to copy local profile databases safely. The targeted browsers include Chrome, Edge, Firefox, Brave, Arc, and privacy-focused alternatives like Zen and LibreWolf.
Targeting Browsers, User Photos, and Cloud Assets
Moreover, the implant collects twenty-one distinct hardware attributes to profile the victim host. It also reads the user account photograph directly from local directory services using command-line tools. After completing data collection, the malware packages the stolen files into a compressed archive. It transmits the archive to remote infrastructure using encrypted HTTP requests carrying a unique authorization token.
Attribution Analysis
Researchers classify the attribution to specific threat actors as unconfirmed. However, the lures and exfiltration targets indicate financially motivated cybercriminals focusing on digital asset theft. Independent security researcher LOpsec also observed related samples that share architectural similarities with this campaign.
Defense and Detection Guidance
Defenders must monitor macOS endpoints for suspicious script executions and hidden LaunchAgent entries. Security administrators should inspect the user Application Support directory for unauthorized applications posing as system components. Furthermore, teams should audit shell configuration files and global Git hooks for unexpected background triggers.
Users should avoid downloading software from unverified third-party websites. Enforcing mobile device management profiles and endpoint detection controls helps block unauthorized script execution.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!