A new variant of the XCSSET macOS modular malware has emerged in attacks that target users' sensitive information, including digital wallets and data from the legitimate Notes app. The malware is typically distributed through infected Xcode projects. It has been around for at least five years and each update represents a milestone in XCSSET's development. The current improvements are the first ones observed since 2022. Microsoft's Threat Intelligence team identified the latest variant in limited attacks and says that compared to past XCSSET variants, the new one features enhanced code obfuscation, better persistence, and new infection strategies. In May 2021, Apple fixed a vulnerability that was actively exploited as a zero-day by XCSSET, an indication of the malware developer's capabilities. Microsoft warns today of new attacks that use a variant of the XCSSET macOS malware with improvements across the board. Some of the key modifications the researchers spotted include: For the zshrc persistence method, the new XCSSET variant creates a file named ~/.zshrc_aliases that contains the payload and appends a command in the ~/.zshrc file. This way, the created file launches whenever a new shell session starts. For the dock method, a signed dockutil tool is downloaded from the attacker's command-and-control (C2) server to manage dock items. XCSSET then creates a malicious Launchpad application with the payload and changes the legitimate app's path to point to the fake one. As a re...
Microsoft spots XCSSET macOS malware variant used for crypto theft
BleepingComputer
·Bill Toulas
·Published Feb 17, 2025
·Updated
Affected Software
4 affected components
Apple macOS
Apple Xcode
Apple Notes
Apple macOS
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a new variant of the XCSSET macOS malware that is being used to steal cryptocurrencies and sensitive user information.
2
What security implications are discussed regarding this malware?
The malware poses a significant threat as it can access and exfiltrate users' sensitive information, including digital wallets and data from the Notes app.
3
What products or software are affected by this malware variant?
The affected software includes Apple macOS, Apple Xcode, and Apple Notes.
4
How is the XCSSET malware typically distributed?
The XCSSET malware is typically distributed through infected files and software.
5
What types of data does the XCSSET malware target?
The malware specifically targets sensitive user information such as digital wallet credentials and data stored in the Notes app.