By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: New macOS XCSSET Variant Targets Firefox with Clipper and Persistence Module
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > New macOS XCSSET Variant Targets Firefox with Clipper and Persistence Module
Tech News

New macOS XCSSET Variant Targets Firefox with Clipper and Persistence Module

By Viral Trending Content 5 Min Read
Share
SHARE

Sep 26, 2025Ravie LakshmananMalware / Browser Security

Cybersecurity researchers have discovered an updated version of a known Apple macOS malware called XCSSET that has been observed in limited attacks.

“This new variant of XCSSET brings key changes related to browser targeting, clipboard hijacking, and persistence mechanisms,” the Microsoft Threat Intelligence team said in a Thursday report.

“It employs sophisticated encryption and obfuscation techniques, uses run-only compiled AppleScripts for stealthy execution, and expands its data exfiltration capabilities to include Firefox browser data. It also adds another persistence mechanism through LaunchDaemon entries.”

XCSSET is the name assigned to a sophisticated modular malware that’s designed to infect Xcode projects used by software developers and unleash its malicious capabilities when it’s being built. Exactly how the malware is distributed remains unclear, but it’s suspected that the propagation relies on the Xcode project files being shared among developers building apps for macOS.

Earlier this March, Microsoft uncovered several enhancements to the malware, highlighting its improved error handling and the use of three different persistence techniques to siphon sensitive data from compromised hosts.

DFIR Retainer Services

The latest variant of XCSSET has been found to incorporate a clipper sub-module that monitors clipboard content for specific regular expression (aka regex) patterns matching various cryptocurrency wallets. In the event of a match, the malware proceeds to substitute the wallet address in the clipboard with an attacker-controlled one to reroute transactions.

The Windows maker also noted that the new iteration introduces changes to the fourth stage of the infection chain, particularly where an AppleScript application is used to run a shell command to fetch the final-stage AppleScript that’s responsible for collecting system information and launching various sub-modules using a boot() function.

Notably, the modifications include extra checks for the Mozilla Firefox browser and an altered logic to determine the presence of the Telegram messaging app. Also observed are changes to the various modules, as well as new modules that did not exist in previous versions –

  • vexyeqj, the information module previously called seizecj, and which downloads a module called bnk that’s run using osascript. The script defines functions for data validation, encryption, decryption, fetching additional data from command-and-control (C2) server, and logging. It also includes the clipper functionality.
  • neq_cdyd_ilvcmwx, a module similar to txzx_vostfdi that exfiltrates files to the C2 server
  • xmyyeqjx, a module to set up LaunchDaemon-based persistence
  • jey, the module previously called jez, and which is used to set up Git-based persistence
  • iewmilh_cdyd, a module to steal data from Firefox using a modified version of a publicly available tool named HackBrowserData
CIS Build Kits

To mitigate the threat posed by XCSSET, users are recommended to ensure that they keep their system up-to-date, inspect Xcode projects downloaded or cloned from repositories or other sources, and exercise caution when it comes to copying and pasting sensitive data from the clipboard.

Sherrod DeGrippo, Director of Threat Intelligence Strategy at Microsoft, told The Hacker News that the modules regularly undergo small name changes as the malware evolves, despite its functionality remaining consistent.

“What stands out in this variant is its ability to intercept and tamper with clipboard content tied to digital wallets,” DeGrippo said. “This isn’t passive reconnaissance; it’s a threat that will undermine trust in something as basic as what you copy and paste.

“The latest XCSSET evolution shows how even developer tools can be weaponized. With tactics like clipboard hijacking, expanded browser targeting, and stealth persistence, threat actors continue to raise the level of sophistication defenders need to guard against.”

(The story was updated after publication to include a response from Microsoft.)

You Might Also Like

The Debate Over Grok 5 and Its Role in Achieving AGI

Atlantia Clinical Trials opens new exercise physiology lab in Cork

Regretting You Film Review: Bland New Colleen Hoover Adaptation

Elon Musk Wants ‘Strong Influence’ Over the ‘Robot Army’ He’s Building

TARmageddon flaw in abandoned Rust library enables RCE attacks

TAGGED: AppleScript, clipboard hijacking, Cyber Security, Cybersecurity, Data Exfiltration, Firefox, Internet, MacOS, Malware, Microsoft, XCSSET
Share This Article
Facebook Twitter Copy Link
Previous Article ChatGPT Pulse and How It Anticipates Your Needs
Next Article 15pc cap on EU pharma exports to US still applies, says Tánaiste
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Littleton maker of vodka, whiskey and gin, 52eighty Distilling files for Chapter 7 bankruptcy
Business
Meet the little-known UK stock that’s smashing the S&P 500’s finest!
Business
Bunni DEX becomes the second crypto project to shut this week
Crypto
Warner Bros. Discovery Has Announced That it is Looking For a Buyer For the Entire Company
Gaming News
High-end housing segment remains hot this Diwali even as overall sales cool off, says Samir Jasuja
Business
Crypto update: Bitcoin and Ethereum are stable as market’s focus shifts to US inflation data
Crypto
Diddy Strikes Back — Files Appeal As SBF’s Ex-Cellmate Joins Legal Rebellion
Crypto

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Littleton maker of vodka, whiskey and gin, 52eighty Distilling files for Chapter 7 bankruptcy

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Littleton maker of vodka, whiskey and gin, 52eighty Distilling files for Chapter 7 bankruptcy
October 23, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?