New PamStealer variant uses live X25519 exchange to decipher payload

Author: Published 6 min de lectura 12 reading

The images in this article were generated with artificial intelligence. How we publish

Cybersecurity researchers have identified a new variant of PamStealer that changes its delivery chain and adds a cryptographic barrier that prevents the recovery of its payload without the collaboration of the control server. According to the analysis published by Jamf Threat Labs and commented by researcher Thijs Xhaflaire, attackers maintain the use of a JavaScript for Automation (JXA )-based dropper but now use it only as a vehicle to launch a shell script that makes a live key exchange with a remote server and downloads a utilitarian called "pkgunpack" that completes the payload decryption. These facts are documented by the researchers and are the confirmed basis of what follows.

Technically, the reported infection chain works in several phases. First the victim is attracted to a fake site - wavel [.] app - that offers a supposed cryptomoneda purse called Wavel. By pressing "Download for macOS" you get a Wavel.dmg file containing a compiled AppleScript; by opening it, the Editor Script runs a JXA fragment that decodes a base64 chain and redirects it to / bin / zsh. That decoded zsh continues in the background and performs three critical actions: download and run "pkgunpack" from wavel.apple03cloud [.] com, make a key exchange X25519 with the server to get the decipher key (DEK) and finally disfigure and deploy the final malware package.

New PamStealer variant uses live X25519 exchange to decipher payload
Image generated with IA.

The crucial technical novelty is the use of an asymmetric key exchange (X25519) that links the decipher capacity to the remote server cooperation. Because the server retains the private key needed to complete the exchange, an analyst who captures the encrypted file will not be able to recover the DEK or the content of the payload statically. In addition, attackers generate a couple of ephemeral keys in each execution, which prevents a DEK value captured in a previous execution from being reused to decipher another instance. In cryptographic terms this makes the sample significantly more difficult to analyze without access to a live command and control session; to understand X25519, you can see the corresponding RFC: RFC 7748 (X25519).

In parallel to cryptographic protection, operators have strengthened the persistence and resilience of implementation. The installer creates four redundant methods of persistence, removes notifications of macOS that alert about new login elements, installs a repair script that restores both the malicious bundle and the LaunchAgent in case of removal and adds a line to the ~ / .zshrc file to run the repair script in each new interactive zsh session. In addition, the repair script is copied in ~ / Library / Application Support / System / .githouks / and is globally configured as Git (git config --global chore.hooksPath), so any git (check out, commit) operation in any active repository in the machine will quietly run that script.

The last step is the execution of the thief component written in Swift (a change from previous versions implemented in Rust). This binary collects passwords - including the technique of showing a false fault dialog to persuade the victim to enter its password, which is then valid by PAM - lists key key elements, steals browser credentials (an extensive list that includes both popular browsers and less common alternatives: Chrome, Edge, Firefox, Brave, Vivaldi, Opera, Arc, Zen, LibreWolf and others), collects the user's history and configuration files (.zsh _ history, .zshrc, .bash _ history, git.config, inventory, and process-based, and process-in-out, and-file-out. These exfiltration behaviors are described by researchers and represent the operational goal of malware.

Who's it to? Mainly to macOS users who download and install software outside official channels or who distrust security signals (unsigned apps, unnotarized DMG). The explicit inclusion of less common and privacy-oriented browsers (Arc, Zen, LibreWolf) suggests that operators seek a diversity of victims, including people who might consider using "safer" alternatives. Local developers and repositories are also at risk because chore.hooksPath manipulation turns any git operation into a reactivation vector.

Practical consequences: the new architecture increases the difficulty for response and analysis teams: without an active C2 session you cannot get the decipher payload for your static analysis, so detection must pivote at dynamic and network signals. The hidden persistence in git hooks and in ~ / .zshrc increases the likelihood of reinfection or malware restoration after initial removal. In addition, the theft of passwords, keychain and browser data has immediate implications of account supplanting, access to financial services and escape of development secrets (tokens, keys stored in .gitconfig or local repositories).

Data confirmed against uncertainties: it is a fact confirmed by Jamf Threat Labs and the cited researcher that the sample incorporates the X25519 exchange, the use of remote pkgunpack and the persistence techniques described. It is a reasonable estimate - but not publicly confirmed - of the scope of the campaign (number of victims and whether the C2 is still operational at this time). Nor is there, as far as researchers report, a firm attribution to who operates the infrastructure; that connection is uncertain and requires more forensic investigation and intelligence correlation.

New PamStealer variant uses live X25519 exchange to decipher payload
Image generated with IA.

Specific measures that every user and manager of macOS should take immediately: do not mount or run DMG or binaries of unverified origins; check for the above-mentioned artifacts (e.g. search ~ / Library / Application Support / System / .githooks, inspect ~ / .zshrc for added hooks and review LaunchAgens recently); audit Git's global configuration with git config --global --list to detect unusual chore.hooksPath; review system login elements (Preferences of the system and verify web-based settings →) as well as user-based and user-based settings. Advanced users and response equipment can use EDR or network monitoring tools to block and record connections to associated domains and capture traffic for analysis.

In addition, and in a preventive way: activate Gatekeeper and demand notarized apps, keep up-to-date macOS and security software, change sensitive passwords and revoke credentials that could have been exposed (especially if there is a suspicion of having opened the DMG), and enable 2FA where possible. If the presence of the devices described above is detected, consider disconnecting the machine from the network to prevent exfiltration and contact your response team or a forensic supplier. To understand the persistence techniques and how they would be mapped to threat frames, see MITRE ATT & CK (e.g. the Launch Agents technique): MITRE ATT & CK - Launch Agent.

Finally, it is important that the detection and response teams adjust their rules to look for the behavior patterns: execution of Script Editor that invokes JXA that decodifies and channels zsh, downloads from unusual domains, creation of global Git hooks routes and modification of ~ / .zshrc Since live encryption limits static analysis, the best opportunities to understand and mitigate the threat go through early identification of the delivery phase and capture of real-time network traffic. For those investigating key exchange techniques and their involvement in malware, the X25519 standard is a good technical reference point: RFC 7748 (X25519).

Coverage

Related

More news on the same subject.