Microsoft says there's a new variant of XCSSET on the prowl for Mac users – the first new iteration of the malware since 2022. XCSSET has been seen in limited attacks thus far, but Apple devs should be especially vigilant since the main infection vector is via Xcode projects. The malware's main capabilities from 2022 remain. It still chases after digital wallet contents and gathers data from Notes and other system files as well. The main updates come in the form of better code obfuscation, updated persistence mechanisms, and new infection methods, Microsoft said in a Monday alert. The key to its new obfuscation techniques is randomization, Microsoft added. Both the methods used for encoding payloads and the number of encoding iterations are "significantly more randomized" compared to previous versions. SentinelOne investigated XCSSET in 2022 and found evidence of randomization, particularly in curl's --max-time value and the script's phaseName variable within the AppleScript payload file. It said at the time these techniques were likely deployed to evade static analysis and threat-hunting rules. Microsoft said that in addition to using xxd for encoding in previous versions, XCSSET also now uses Base64, and module names are obfuscated, too, increasing the difficulty involved in determining the functionality of each. Microsoft detailed two methods used to establish persistence. The first is the zshrc method, which ensures the malware persists across shell sessions. The payload ...
XCSSET macOS malware returns with first new version since 2022
The Register
·Connor Jones
·Published Feb 17, 2025
·Updated
Affected Software
3 affected components
macOS
Apple Xcode
Microsoft XCSSET
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the return of a new variant of the XCSSET malware targeting macOS users.
2
What security implications are discussed in relation to the XCSSET malware?
The article highlights that the new variant poses a risk to Mac users, particularly affecting Apple developers.
3
When was the last known version of XCSSET released before this new variant?
The previous version of XCSSET was noted to be active until 2022.
4
What specific software is mentioned as being affected by the XCSSET malware?
The affected software includes Apple macOS, Apple Xcode, and Microsoft XCSSET.
5
Who should be particularly cautious regarding the XCSSET malware?
Apple developers should remain especially vigilant due to the malware's targeting.