By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Microsoft Uncovers New XCSSET macOS Malware Variant with Advanced Obfuscation Tactics
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Microsoft Uncovers New XCSSET macOS Malware Variant with Advanced Obfuscation Tactics
Tech News

Microsoft Uncovers New XCSSET macOS Malware Variant with Advanced Obfuscation Tactics

By Viral Trending Content 3 Min Read
Share
SHARE

Feb 17, 2025Ravie LakshmananEndpoint Security / Malware

XCSSET macOS Malware

Microsoft said it has discovered a new variant of a known Apple macOS malware called XCSSET as part of limited attacks in the wild.

“Its first known variant since 2022, this latest XCSSET malware features enhanced obfuscation methods, updated persistence mechanisms, and new infection strategies,” the Microsoft Threat Intelligence team said in a post shared on X.

“These enhanced features add to this malware family’s previously known capabilities, like targeting digital wallets, collecting data from the Notes app, and exfiltrating system information and files.”

Cybersecurity

XCSSET is a sophisticated modular macOS malware that’s known to target users by infecting Apple Xcode projects. It was first documented by Trend Micro in August 2020.

Subsequent iterations of the malware have been found to adapt to compromise newer versions of macOS as well as Apple’s own M1 chipsets. In mid-2021, the cybersecurity company noted that XCSSET had been updated to exfiltrate data from various apps like Google Chrome, Telegram, Evernote, Opera, Skype, WeChat, and Apple first-party apps such as Contacts and Notes.

Another report from Jamf around the same time revealed the malware’s ability to exploit CVE-2021-30713, a Transparency, Consent, and Control (TCC) framework bypass bug, as a zero-day to take screenshots of the victim’s desktop without requiring additional permissions.

Then, over a year later, it was updated again to add support for macOS Monterey. As of writing, the origins of the malware remain unknown.

The latest findings from Microsoft mark the first major revision since 2022, using improved obfuscation methods and persistence mechanisms that are aimed at challenging analysis efforts and ensuring that the malware is launched every time a new shell session is initiated.

Cybersecurity

Another novel manner XCSSET sets up persistence entails downloading a signed dockutil utility from a command-and-control server to manage the dock items.

“The malware then creates a fake Launchpad application and replaces the legitimate Launchpad’s path entry in the dock with this fake one,” Microsoft said. “This ensures that every time the Launchpad is started from the dock, both the legitimate Launchpad and the malicious payload are executed.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor

Claude Sonic 4.8 Leaks and Anthropic’s Jupiter Model

Max severity Cisco Secure Workload flaw gives Site Admin privileges

WhatsApp ads could make Irish debut after discussions with DPC

Best Duffel Bags: Eastpak, Patagonia, Baboon to the Moon (2026)

TAGGED: Apple, Cyber Security, Cybersecurity, Data Exfiltration, Internet, MacOS, Malware, Microsoft, Threat Intelligence, XCSSET
Share This Article
Facebook Twitter Copy Link
Previous Article Musk's DOGE seeks access to US tax system: Reports
Next Article Avowed Is Wonderful, But Could My Companions Please Just Shush?
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor
Tech News
Claude Sonic 4.8 Leaks and Anthropic’s Jupiter Model
Tech News
Max severity Cisco Secure Workload flaw gives Site Admin privileges
Tech News
Last Night In Baseball: Dodgers Superstar Shohei Ohtani Dazzles Against Padres
Sports
McKinsey partner says up to 50% of work hours could be transformed within the next 5 years
Business
Aster price gains amid 300% volume spike – can it mirror HYPE rally?
Crypto
‘Historic’ UK trade deal with Gulf states set to add billions to British economy
World News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor
May 21, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?