• News/
  • https://www.theregister.com/2025/02/17/macos_xcsset_malware_returns/

XCSSET macOS malware returns with first new version since 2022

The Register
·
Connor Jones
·
Published Feb 17, 2025
·
Updated

Microsoft says there's a new variant of XCSSET on the prowl for Mac users – the first new iteration of the malware since 2022. XCSSET has been seen in limited attacks thus far, but Apple devs should be especially vigilant since the main infection vector is via Xcode projects. The malware's main capabilities from 2022 remain. It still chases after digital wallet contents and gathers data from Notes and other system files as well. The main updates come in the form of better code obfuscation, updated persistence mechanisms, and new infection methods, Microsoft said in a Monday alert. The key to its new obfuscation techniques is randomization, Microsoft added. Both the methods used for encoding payloads and the number of encoding iterations are "significantly more randomized" compared to previous versions. SentinelOne investigated XCSSET in 2022 and found evidence of randomization, particularly in curl's --max-time value and the script's phaseName variable within the AppleScript payload file. It said at the time these techniques were likely deployed to evade static analysis and threat-hunting rules. Microsoft said that in addition to using xxd for encoding in previous versions, XCSSET also now uses Base64, and module names are obfuscated, too, increasing the difficulty involved in determining the functionality of each. Microsoft detailed two methods used to establish persistence. The first is the zshrc method, which ensures the malware persists across shell sessions. The payload ...

Read full article

Affected Software

3 affected components
macOS
Apple Xcode
Microsoft XCSSET
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the return of a new variant of the XCSSET malware targeting macOS users.

2

What security implications are discussed in relation to the XCSSET malware?

The article highlights that the new variant poses a risk to Mac users, particularly affecting Apple developers.

3

When was the last known version of XCSSET released before this new variant?

The previous version of XCSSET was noted to be active until 2022.

4

What specific software is mentioned as being affected by the XCSSET malware?

The affected software includes Apple macOS, Apple Xcode, and Microsoft XCSSET.

5

Who should be particularly cautious regarding the XCSSET malware?

Apple developers should remain especially vigilant due to the malware's targeting.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203