Back to news

Mac Stealer Hijacks Clipboard App, FBI Shuts Residential Proxy Botnet

Two separate cybersecurity actions this week expose how attackers abuse trusted software and compromised home networks to reach enterprise targets.

Mac Stealer Hijacks Clipboard App, FBI Shuts Residential Proxy Botnet

What happened

Jamf Threat Labs identified a macOS credential-stealing malware, dubbed PamStealer, distributed as a counterfeit version of Maccy, a well-regarded open-source clipboard manager. The payload arrives as a compiled AppleScript file and exploits macOS's Pluggable Authentication Module framework to harvest login passwords from infected machines. Separately, the FBI announced the seizure of hundreds of domains tied to NetNut, a residential proxy network operated by Nasdaq-listed Israeli firm Alarum Technologies. The action followed reporting that linked NetNut's infrastructure to the Popa botnet, which quietly recruited ordinary users' devices into a for-hire traffic-routing service.

Why it matters for your business

PamStealer is a reminder that macOS is no longer a low-priority attack surface — credential theft via a spoofed productivity tool requires no exploit, only a distracted employee downloading software from an unofficial source. Security teams should enforce app installation policies that restrict downloads to the Mac App Store or verified developer signatures, and confirm that endpoint detection tools cover AppleScript-based payloads. The NetNut takedown illustrates a broader risk: corporate traffic increasingly brushes against residential proxy networks whose nodes may be compromised consumer devices. Organizations relying on IP-reputation filters or geolocation controls should understand that such services can make malicious requests appear to originate from clean residential addresses, undermining fraud-detection and access-control systems.

What to watch next

Regulatory scrutiny of dual-use proxy services is intensifying, and Alarum Technologies' public listing makes any further legal developments market-relevant for investors and partners. On the malware front, researchers will be examining whether PamStealer shares infrastructure or code lineage with other macOS stealers circulating on dark-web marketplaces. Enterprises should watch for follow-on advisories from Apple and Jamf as the scope of affected systems becomes clearer.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp