• News/
  • https://www.bleepingcomputer.com/news/security/microsoft-spots-xcsset-macos-malware-variant-used-for-crypto-theft/

Microsoft spots XCSSET macOS malware variant used for crypto theft

BleepingComputer
·
Bill Toulas
·
Published Feb 17, 2025
·
Updated

A new variant of the XCSSET macOS modular malware has emerged in attacks that target users' sensitive information, including digital wallets and data from the legitimate Notes app. The malware is typically distributed through infected Xcode projects. It has been around for at least five years and each update represents a milestone in XCSSET's development. The current improvements are the first ones observed since 2022. Microsoft's Threat Intelligence team identified the latest variant in limited attacks and says that compared to past XCSSET variants, the new one features enhanced code obfuscation, better persistence, and new infection strategies. In May 2021, Apple fixed a vulnerability that was actively exploited as a zero-day by XCSSET, an indication of the malware developer's capabilities. Microsoft warns today of new attacks that use a variant of the XCSSET macOS malware with improvements across the board. Some of the key modifications the researchers spotted include: For the zshrc persistence method, the new XCSSET variant creates a file named ~/.zshrc_aliases that contains the payload and appends a command in the ~/.zshrc file. This way, the created file launches whenever a new shell session starts. For the dock method, a signed dockutil tool is downloaded from the attacker's command-and-control (C2) server to manage dock items. XCSSET then creates a malicious Launchpad application with the payload and changes the legitimate app's path to point to the fake one. As a re...

Read full article

Affected Software

4 affected components
Apple macOS
Apple Xcode
Apple Notes
Apple macOS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new variant of the XCSSET macOS malware that is being used to steal cryptocurrencies and sensitive user information.

2

What security implications are discussed regarding this malware?

The malware poses a significant threat as it can access and exfiltrate users' sensitive information, including digital wallets and data from the Notes app.

3

What products or software are affected by this malware variant?

The affected software includes Apple macOS, Apple Xcode, and Apple Notes.

4

How is the XCSSET malware typically distributed?

The XCSSET malware is typically distributed through infected files and software.

5

What types of data does the XCSSET malware target?

The malware specifically targets sensitive user information such as digital wallet credentials and data stored in the Notes app.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203