INTEL_REPORT
Ars Technica — Security · published 7/2/2026, 7:38:57 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Newly discovered PamStealer isn't your typical macOS malware The discovery underscores the increased effort being poured into Mac infostealers. Researchers have found a never-before-seen piece of macOS malware that combines a series of clever tradecraft to infect Macs with stealthy, custom-developed credential-stealing code. The malware is delivered in two stages. The first is distributed in a disk image that masquerades as Maccy , a clipboard manager for Macs. It’s compile…
https://arstechnica.com/security/2026/07/new-pamstealer-macos-malware-uses-clever-tradecraft-to-remain-stealthy
sha256:cb114ed15abe68e3a10aaf197a8366b2689a8ac0e148df34e1547f8a7826b140
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
No indicators linked for this report.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.