By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Microsoft Uncovers New XCSSET macOS Malware Variant with Advanced Obfuscation Tactics
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Microsoft Uncovers New XCSSET macOS Malware Variant with Advanced Obfuscation Tactics
Computing

Microsoft Uncovers New XCSSET macOS Malware Variant with Advanced Obfuscation Tactics

News Room
Last updated: 2025/02/17 at 12:17 PM
News Room Published 17 February 2025
Share
SHARE

Feb 17, 2025Ravie LakshmananEndpoint Security / Malware

Microsoft said it has discovered a new variant of a known Apple macOS malware called XCSSET as part of limited attacks in the wild.

“Its first known variant since 2022, this latest XCSSET malware features enhanced obfuscation methods, updated persistence mechanisms, and new infection strategies,” the Microsoft Threat Intelligence team said in a post shared on X.

“These enhanced features add to this malware family’s previously known capabilities, like targeting digital wallets, collecting data from the Notes app, and exfiltrating system information and files.”

Cybersecurity

XCSSET is a sophisticated modular macOS malware that’s known to target users by infecting Apple Xcode projects. It was first documented by Trend Micro in August 2020.

Subsequent iterations of the malware have been found to adapt to compromise newer versions of macOS as well as Apple’s own M1 chipsets. In mid-2021, the cybersecurity company noted that XCSSET had been updated to exfiltrate data from various apps like Google Chrome, Telegram, Evernote, Opera, Skype, WeChat, and Apple first-party apps such as Contacts and Notes.

Another report from Jamf around the same time revealed the malware’s ability to exploit CVE-2021-30713, a Transparency, Consent, and Control (TCC) framework bypass bug, as a zero-day to take screenshots of the victim’s desktop without requiring additional permissions.

Then, over a year later, it was updated again to add support for macOS Monterey. As of writing, the origins of the malware remain unknown.

The latest findings from Microsoft mark the first major revision since 2022, using improved obfuscation methods and persistence mechanisms that are aimed at challenging analysis efforts and ensuring that the malware is launched every time a new shell session is initiated.

Cybersecurity

Another novel manner XCSSET sets up persistence entails downloading a signed dockutil utility from a command-and-control server to manage the dock items.

“The malware then creates a fake Launchpad application and replaces the legitimate Launchpad’s path entry in the dock with this fake one,” Microsoft said. “This ensures that every time the Launchpad is started from the dock, both the legitimate Launchpad and the malicious payload are executed.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Presidents’ Day Deal: The Lowest Price We’ve Ever Seen for This Dyson Airwrap
Next Article Dublin-based software firm Aspera Solutions aims to triple growth with global expansion
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

How to Use Gemini in Google Meet for Seamless Collaboration
Computing
AI biotech firm SpotitEarly raises $20.3M to scale noninvasive cancer detection in US – News
News
The Best Hearing Aids
Gadget
A Symphony of Savings: This JBL Bar Soundbar Turns Down Its Price by $400
News

You Might also Like

Computing

How to Use Gemini in Google Meet for Seamless Collaboration

16 Min Read
Computing

Power Up Your Survival Analysis: BayesPPDSurv Makes History (and Futures)! | HackerNoon

6 Min Read
Computing

Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails

3 Min Read
Computing

JD.com reports 5.1% revenue growth in Q3 2024 · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?