• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Microsoft Warns of Updated XCSSET macOS Malware Monitoring Clipboard to Hijack Cryptocurrency Transactions
Share
  • bitcoinBitcoin(BTC)$76,509.00
  • ethereumEthereum(ETH)$2,281.61
  • tetherTether(USDT)$1.00
  • rippleXRP(XRP)$1.39
  • binancecoinBNB(BNB)$623.08
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$83.72
  • tronTRON(TRX)$0.323496
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03
  • dogecoinDogecoin(DOGE)$0.099164
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
News

Microsoft Warns of Updated XCSSET macOS Malware Monitoring Clipboard to Hijack Cryptocurrency Transactions

News Desk
Last updated: September 26, 2025 2:13 pm
News Desk
Published: September 26, 2025
Share
MacOS Mac malware Apple

An updated variant of the sophisticated XCSSET malware targeting macOS is raising alarms after Microsoft issued a warning regarding its clipboard monitoring capabilities, specifically aimed at hijacking cryptocurrency transactions.

XCSSET was first identified in the wild about five years ago and primarily spreads through malicious Xcode projects, exploiting Apple’s integrated development environment designed for macOS development. Initially crafted to steal sensitive information from chat applications and files, inject malicious code into websites, and deliver ransom notes, the malware has undergone numerous updates to enhance its functionality.

The latest iteration introduces an additional persistence mechanism, modifies its browser targeting strategies, and augments its clipboard hijacking features. This latest version operates through a complex four-stage infection chain. Notably, modifications to its boot function now include supplementary checks specifically targeting the Firefox browser and a refined verification process for the Telegram app.

During the final stage of its infection process, the malware retrieves a compiled AppleScript designed to handle functions related to data validation, encryption, and decryption. Furthermore, it gathers additional data from its command-and-control (C&C) server. A key feature of this script is its clipboard monitoring capability, which enables the malware to identify cryptocurrency wallet addresses and substitute them with those controlled by the attackers.

In addition to these capabilities, XCSSET has been observed downloading a secondary script from the C&C server that possesses file exfiltration functionalities. The malware establishes persistence by creating a file within the user’s home directory to store the payload, along with modifying system settings to disable important macOS security updates and the Rapid Security Response mechanism.

Moreover, the new variant creates a counterfeit system settings application, which executes functions that wait for users to launch the legitimate System Settings app before activating the impostor, thereby masquerading as a trustworthy application.

Notably, this version of XCSSET includes an information-stealing module targeting the Firefox browser. This module, adapted from the open-source HackBrowserData project, aims to pilfer browser history, cookies, and saved passwords, including credit card information.

Microsoft has reported its findings to Apple and collaborated with GitHub to eliminate malicious repositories linked to the malware. Although this variant of XCSSET is currently observed in limited attacks, Microsoft emphasizes the importance of heightening awareness regarding this evolving threat to ensure user safety.

Crypto.com Partners with Morpho to Launch DeFi-backed Loans for Customers
Trump Media Files for Two New Cryptocurrency ETFs Tied to Bitcoin, Ether, and Cronos
Georgia Partners with Hedera to Move National Real Estate Registry On-Chain
The Risks of Timing the Market During Global Turmoil
U.S. Inflation Rises 3% as Trump Administration Faces Economic Criticism
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article fce02a46 89e7 45cf aa25 1bf83ebed7b0 Search for Top Crypto Presales Heats Up: Pudgy Penguins and BlockchainFX Eye 2025
Next Article 1758896732 blockchain Chainlink’s Potential Growth as It Trades Below Record Highs
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
107428988 1718330300365 gettyimages 2154653061 AFP 34UB8PH
Bank of Japan Holds Rates Amid Dissent, Global Markets React
69efcfc53fecbb42897a4b76
Market Lessons Learned from Tariff Chaos of 2025 to Iran War Volatility of 2026
L428151168 g
New Crypto Coins 2026: Blazpay Leads the Surge
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Company
  • Finance
  • Stocks
  • News
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?