SECURITY·중요도 8·2026. 09. 25.·The Hacker News
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
── KO ──────────────────
PamStealer 맬웨어가 라이브 C2 페이로드 복호화 및 다중 계층 지속성 기능을 추가했습니다.
사이버 보안 연구자들이 PamStealer의 새로운 버전을 발견했습니다. 이 버전은 서버 측 복호화 체인을 사용하여 주 페이로드를 복구할 수 있도록 하여 보안성을 강화했습니다. Jamf Threat Labs에 따르면, 이 맬웨어는 여전히 JavaScript 자동화(JXA)에 의존하나, 유혹 및 전달 방식에서 수정이 이루어졌습니다.
── EN ──────────────────
PamStealer malware adds live C2 payload decryption and multi-layer persistence features.
Cybersecurity researchers have flagged a new version of PamStealer that enhances security by ensuring the main payload can only be recovered using a server-side decryption chain. According to Jamf Threat Labs, the malware still relies on the JavaScript for Automation (JXA) dropper mechanism, but modifies both the lure and the delivery method.