Malware & Threats

Microsoft Warns of Improved XCSSET macOS Malware

Microsoft has observed a new variant of the XCSSET malware being used in limited attacks against macOS users.

macOS malware

A new variant of the sophisticated XCSSET malware has been observed in recent, limited attacks against macOS users, Microsoft reports.

First seen in 2020, XCSSET spreads through Apple Xcode, the integrated development environment for macOS: threat actors inject malicious code into Xcode projects, and the victim’s system is infected when the project is executed.

The malware was designed to steal information associated with numerous chat applications, take screenshots, inject JavaScript code into websites, encrypt files and drop ransom notes, and upload files to the attackers’ server.

At the time of discovery, it was also exploiting two zero-day vulnerabilities to steal a Safari cookie file and to run the development version of the browser when the victim attempted to launch Safari.

An XCSSET variant observed in 2021 was specifically targeting devices powered by Apple’s M1 chip, which uses an arm64 CPU architecture.

Now, Microsoft has identified a new XCSSET variant that relies on new obfuscation methods, uses an updated persistence mechanism, and leverages new infection methods.

Advertisement. Scroll to continue reading.

The malware now uses increased randomization when generating payloads to be injected into Xcode projects, drops the payload in a file that is executed when a new shell session is launched, and replaces the Launchpad’s dock path entry with a fake application to execute the payload, Microsoft explains.

“These enhanced features add to this malware family’s previously known capabilities, like targeting digital wallets, collecting data from the Notes app, and exfiltrating system information and files,” Microsoft notes in a post on X (formerly Twitter).

Additionally, the tech giant observed the updated malware variant using new methods for where the malicious payload is placed in an Xcode project.

“The method is chosen from one of the following options: TARGET, RULE, or FORCED_STRATEGY. An additional method involves placing the payload inside the TARGET_DEVICE_FAMILY key under build settings and running it at a later phase,” Microsoft notes.

Related: Homebrew macOS Users Targeted With Information Stealer Malware

Related: 22 New Mac Malware Families Seen in 2024

Related: Banshee macOS Malware Expands Targeting

Related: NotLockBit Ransomware Can Target macOS Devices

Related Content

Cybercrime

Researchers say the OnyxC2 malware targets more than 200 applications and extensions while evading detection through encrypted payloads, DLL sideloading, and in-memory execution techniques.

ICS/OT

A PowerShell script included in patch files appears to be triggering false positives by multiple security engines.

Identity & Access

As attackers increasingly favor stolen credentials over exploits, infostealers have become a primary source of access for ransomware and other cybercrime operations.

Artificial Intelligence

Researchers warn GreyVibe’s extensive use of ChatGPT, Gemini, and other AI tools offers a glimpse into how future cybercriminal and state-aligned groups will operate.

Malware & Threats

Delivered via phishing lures, the malware combines financial theft with data exfiltration and remote access.

Supply Chain Security

Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets.

Malware & Threats

 Fox Tempest provides a service that cybercriminals use to distribute ransomware and other malware disguised as legitimate software.

Endpoint Security

Attackers are increasingly abusing Microsoft’s decades-old MSHTA utility to stealthily deliver stealers, loaders, and persistent malware through phishing, fake software downloads, and LOLBIN-based attack...

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version