A new variant of the XCSSET macOS malware has been identified by Microsoft Threat Intelligence, demonstrating significant advancements in its capabilities and targeting. This updated version of XCSSET is specifically designed to infect Xcode projects, which are commonly used by software developers building applications for macOS. The malware leverages the sharing of Xcode project files among developers as its primary propagation method, allowing it to spread stealthily within development environments. Researchers have observed that the latest variant introduces sophisticated encryption and obfuscation techniques, making detection and analysis more challenging. One of the key enhancements is the use of run-only compiled AppleScripts, which enable stealthy execution and help evade security tools. The malware has expanded its data exfiltration capabilities to include the theft of browser data from Mozilla Firefox, in addition to previously targeted browsers. To achieve this, it installs a modified build of the open-source HackBrowserData tool, which is capable of decrypting and exporting sensitive browser data. Another notable feature is the addition of a clipper sub-module that actively monitors the system clipboard for patterns matching cryptocurrency wallet addresses. When such an address is detected, the malware replaces it with an attacker-controlled address, effectively hijacking cryptocurrency transactions and redirecting funds to the threat actors. The persistence mechanisms have also been improved, with the malware now creating LaunchDaemon entries and deploying a fake System Settings.app in the /tmp directory to maintain its foothold on compromised systems. The infection chain has been updated, particularly in the fourth stage, where an AppleScript application is used to execute a shell command that fetches the final-stage AppleScript responsible for system information collection and launching various sub-modules. Microsoft notes that the new variant has been observed only in limited attacks so far, but its advanced features and modular design pose a significant threat to macOS users, especially developers. The malware's ability to siphon sensitive data, including Notes, browser credentials, and cryptocurrency wallets, increases the risk of financial loss and data breaches. Enhanced error handling and the use of multiple persistence techniques further complicate remediation efforts. Microsoft has shared its findings with Apple to aid in the development of detection and mitigation strategies. The exact initial distribution vector remains unclear, but the reliance on infected Xcode projects highlights the importance of secure development practices. Organizations and individual developers are urged to review their Xcode environments for signs of compromise and to implement robust endpoint protection solutions. The discovery of this new XCSSET variant underscores the evolving threat landscape for macOS and the need for continuous vigilance among software development communities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Public reporting on Microsoft's findings revealed that the new XCSSET variant added capabilities such as targeting Firefox, clipboard hijacking for cryptocurrency theft, and updated persistence techniques. Multiple outlets covered these same technical details as part of the same disclosure.
Microsoft uncovered a fresh variant of the XCSSET macOS malware being used in targeted attacks against Xcode developers via infected Apple development projects. The discovery marked the first reported emergence of this updated strain in the referenced coverage.
6 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcego.theregister.com
Open sourcetheregister.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.