• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: New Variant of XCSSET macOS Malware Detected with Enhanced Features and Targeting
Share
  • bitcoinBitcoin(BTC)$76,435.00
  • ethereumEthereum(ETH)$2,297.63
  • tetherTether(USDT)$1.00
  • rippleXRP(XRP)$1.38
  • binancecoinBNB(BNB)$624.02
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$83.83
  • tronTRON(TRX)$0.322633
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.04
  • dogecoinDogecoin(DOGE)$0.099748
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
News

New Variant of XCSSET macOS Malware Detected with Enhanced Features and Targeting

News Desk
Last updated: September 26, 2025 5:49 pm
News Desk
Published: September 26, 2025
Share
Apple Finder Mac headpic

A new variant of the XCSSET malware targeting macOS systems has been identified by Microsoft Threat Intelligence. This updated version, detected in limited attacks, introduces several advanced features aimed at enhancing its capabilities, particularly with browser targeting, clipboard hijacking, and improved persistence mechanisms.

XCSSET is recognized as a modular malware designed to steal information and cryptocurrencies, with the ability to extract data from Notes and various cryptocurrency wallets, as well as browser histories from affected devices. Its propagation relies on detecting and infecting Xcode projects, which are commonly utilized by software developers. The malware executes during the building of infected projects, capitalizing on the collaborative nature of development work for Apple or macOS applications.

Microsoft’s analysis reveals significant updates in the new malware variant, especially in its data theft strategies. It now includes functionality to extract data from Firefox by utilizing a modified version of the open-source HackBrowserData tool. This enhancement allows the malware to decrypt and export valuable browser data stored by users.

Furthermore, the malware has evolved its clipboard hijacking capabilities. The update allows it to monitor the macOS clipboard for cryptocurrency address patterns. When it detects such an address, the malware seamlessly replaces it with one controlled by the attackers. Consequently, any cryptocurrency transactions initiated by the user on an infected device could be redirected to the attackers, potentially leading to significant financial losses.

In its quest for persistence, the new variant utilizes advanced techniques, such as creating LaunchDaemon entries that trigger a hidden payload and establishing a counterfeit System Settings.app in the /tmp directory. This deceptive maneuver aims to mask its malicious activities from users and security scrutiny.

Currently, this variant has not been widespread; Microsoft reports that its presence has only been noted in a handful of attacks. Researchers have promptly communicated their findings to Apple and are collaborating with GitHub to eliminate any associated repositories that may harbor the malware.

To mitigate risks associated with XCSSET and similar threats, users are urged to maintain updated versions of macOS and its applications. Microsoft emphasizes the importance of vigilance for developers, who should thoroughly inspect Xcode projects shared with them before proceeding with any builds, particularly as XCSSET has previously leveraged both zero-day vulnerabilities and other exploits in its operations.

US stock futures dip as strong GDP growth raises bets on Fed rate pauses
XRP Shows Bullish Momentum as Analyst Predicts Potential Price Target of $127
Bitcoin’s Slide Raises Questions About Potential Bear Market as November Sees Weakness
G Love Loses Retirement Fund in Online Crypto Scam
Forward Industries Pioneers Corporate Treasury Management with $1.65 Billion Solana Investment
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article Erastus 2025 09 25T145006.490 1 1000x600 20 Million XRP Transfer Signals Potential Accumulation Amid Mixed Market Sentiment
Next Article news story Ripple’s RLUSD Stablecoin Now Listed on Bybit Exchange
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
bitcoin mining decrypt style 03 gID 7
Bernstein Reduces IREN Price Target Amid Shift to AI Cloud and Bitcoin Mining Scale-Down
9cfbbb54fa83d5ef950d60cab7ecbc6f3e9f32ab
Chainlink Reports Successful Q1 2026 with Institutional Partnerships and DeFi Advancements
69f0a9b7367066d7c2971c77
OpenAI’s Missed Targets Trigger Tech Sector Sell-Off
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Company
  • Finance
  • Stocks
  • News
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?