CyberSecurity news

FlagThis

info@thehackernews.com (The Hacker News)@The Hacker News - 10d
Microsoft has uncovered a new variant of the XCSSET macOS malware, marking the first major revision since 2022. This latest version features enhanced obfuscation methods, updated persistence mechanisms, and new infection strategies. The malware is spread through infected Xcode projects, posing a significant risk to Apple developers.

The new XCSSET variant uses more randomized encoding methods, including Base64 in addition to xxd, and obfuscates module names to make analysis more difficult. The malware also employs a "dock method" where a fake Launchpad application is created, replacing the legitimate Launchpad's path in the dock, ensuring the malicious payload executes every time Launchpad is started. Microsoft advises users to inspect Xcode projects before using them and only install apps from trusted sources.
Original img attribution: https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEghg1SN_TvO54oykp9sPzoxHHWcr8ghDkpZ5UDohs9m25I7YHUEciCUjQfJnj-SZqaDVHZ_O-YQCBtOoxxx_pxWRcr63LXSWgDT1EWsTj-MmGBFJ-2JTK7bovHPW_sTR7Ok3v9WibvYESn9NNknA4qKaq6wasx3u2SR5wxNQTYnGSeLrcf4QQTqv4hugWfQ/s728-rw-e365/macos.png
ImgSrc: blogger.googleu

Share: bluesky twitterx--v2 facebook--v1 threads


References :
  • Talkback Resources: Talkback.sh article summarizing Microsoft's discovery of an advanced XCSSET malware variant for macOS.
  • The Hacker News: The Hacker News article about Microsoft uncovering a new XCSSET macOS malware variant with advanced obfuscation tactics.
  • www.bleepingcomputer.com: Microsoft spots XCSSET macOS malware variant used for crypto theft
  • Help Net Security: The XCSSET info-stealing malware is back, targeting macOS users and devs
  • securityonline.info: XCSSET Malware Returns with Enhanced Capabilities to Target macOS Users
  • www.helpnetsecurity.com: The XCSSET info-stealing malware is back, targeting macOS users and devs
  • ciso2ciso.com: Source: thehackernews.com – Author: . Microsoft said it has discovered a new variant of a known Apple macOS malware called XCSSET as part of limited attacks in the wild.
  • The Register: XCSSET macOS malware returns with first new version since 2022 Known for popping zero-days of yesteryear, Microsoft puts Apple devs on high alert Microsoft says there's a new variant of XCSSET on the prowl for Mac users – the first new iteration of the malware since 2022.…
  • ciso2ciso.com: Microsoft Uncovers New XCSSET macOS Malware Variant with Advanced Obfuscation Tactics – Source:thehackernews.com
  • go.theregister.com: XCSSET macOS malware returns with first new version since 2022 Known for popping zero-days of yesteryear, Microsoft puts Apple devs on high alert Microsoft says there's a new variant of XCSSET on the prowl for Mac users – the first new iteration of the malware since 2022.…
  • BleepingComputer: Microsoft Uncovers New XCSSET macOS Malware Variant with Advanced Obfuscation Tactics
  • securityaffairs.com: New XCSSET macOS malware variant used in limited attacks
Classification:
  • HashTags: #XCSSET #macOS #Malware
  • Company: Apple
  • Target: Apple macOS systems
  • Product: macOS
  • Feature: enhanced obfuscation, persiste
  • Malware: XCSSET
  • Type: Malware
  • Severity: Medium