• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Microsoft Warns of Updated XCSSET macOS Malware Monitoring Clipboard to Hijack Cryptocurrency Transactions
Share
  • bitcoinBitcoin(BTC)$64,512.00
  • ethereumEthereum(ETH)$1,747.64
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$591.15
  • usd-coinUSDC(USDC)$1.00
  • rippleXRP(XRP)$1.18
  • solanaSolana(SOL)$71.81
  • tronTRON(TRX)$0.320778
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02
  • HyperliquidHyperliquid(HYPE)$71.90
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
News

Microsoft Warns of Updated XCSSET macOS Malware Monitoring Clipboard to Hijack Cryptocurrency Transactions

News Desk
Last updated: September 26, 2025 2:13 pm
News Desk
Published: September 26, 2025
Share
MacOS Mac malware Apple

An updated variant of the sophisticated XCSSET malware targeting macOS is raising alarms after Microsoft issued a warning regarding its clipboard monitoring capabilities, specifically aimed at hijacking cryptocurrency transactions.

XCSSET was first identified in the wild about five years ago and primarily spreads through malicious Xcode projects, exploiting Apple’s integrated development environment designed for macOS development. Initially crafted to steal sensitive information from chat applications and files, inject malicious code into websites, and deliver ransom notes, the malware has undergone numerous updates to enhance its functionality.

The latest iteration introduces an additional persistence mechanism, modifies its browser targeting strategies, and augments its clipboard hijacking features. This latest version operates through a complex four-stage infection chain. Notably, modifications to its boot function now include supplementary checks specifically targeting the Firefox browser and a refined verification process for the Telegram app.

During the final stage of its infection process, the malware retrieves a compiled AppleScript designed to handle functions related to data validation, encryption, and decryption. Furthermore, it gathers additional data from its command-and-control (C&C) server. A key feature of this script is its clipboard monitoring capability, which enables the malware to identify cryptocurrency wallet addresses and substitute them with those controlled by the attackers.

In addition to these capabilities, XCSSET has been observed downloading a secondary script from the C&C server that possesses file exfiltration functionalities. The malware establishes persistence by creating a file within the user’s home directory to store the payload, along with modifying system settings to disable important macOS security updates and the Rapid Security Response mechanism.

Moreover, the new variant creates a counterfeit system settings application, which executes functions that wait for users to launch the legitimate System Settings app before activating the impostor, thereby masquerading as a trustworthy application.

Notably, this version of XCSSET includes an information-stealing module targeting the Firefox browser. This module, adapted from the open-source HackBrowserData project, aims to pilfer browser history, cookies, and saved passwords, including credit card information.

Microsoft has reported its findings to Apple and collaborated with GitHub to eliminate malicious repositories linked to the malware. Although this variant of XCSSET is currently observed in limited attacks, Microsoft emphasizes the importance of heightening awareness regarding this evolving threat to ensure user safety.

NZD/USD Declines Amid Trade Headwinds and Hawkish RBNZ Outlook
Ripple Launches Corporate Treasury for XRP and RLUSD, Marking Major Milestone
Robinhood Launches Developers’ Version of Its Blockchain, Robinhood Chain, at Consensus Event
Stocks to Hold During the Next Market Crash
Jerry Bruckheimer Reflects on His 50-Year Hollywood Career and the Success of ‘F1’
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article fce02a46 89e7 45cf aa25 1bf83ebed7b0 Search for Top Crypto Presales Heats Up: Pudgy Penguins and BlockchainFX Eye 2025
Next Article 1758896732 blockchain Chainlink’s Potential Growth as It Trades Below Record Highs
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
USD Bullish Tendency 1 Medium
USD/CAD Rises as Fed Signals Potential Interest Rate Hikes Amid US-Iran Tensions
b5cd3bf36d1eac21a178cc65ec243a52a29b099a 1280x854
Bitcoin and Ether ETFs Experience Significant Outflows as Fed Takes Hawkish Turn
BlockDAG Top Cryptos For 2026
BlockDAG’s 5,000 TPS Network Milestone Positions It as Leading Cryptocurrency for Huge Gains
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Company
  • Finance
  • Stocks
  • Bitcoin
  • News
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?