• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: New Variant of XCSSET macOS Malware Detected with Enhanced Features and Targeting
Share
  • bitcoinBitcoin(BTC)$64,030.00
  • ethereumEthereum(ETH)$1,675.96
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$607.78
  • usd-coinUSDC(USDC)$1.00
  • rippleXRP(XRP)$1.14
  • solanaSolana(SOL)$68.14
  • tronTRON(TRX)$0.317212
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03
  • dogecoinDogecoin(DOGE)$0.087668
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
News

New Variant of XCSSET macOS Malware Detected with Enhanced Features and Targeting

News Desk
Last updated: September 26, 2025 5:49 pm
News Desk
Published: September 26, 2025
Share
Apple Finder Mac headpic

A new variant of the XCSSET malware targeting macOS systems has been identified by Microsoft Threat Intelligence. This updated version, detected in limited attacks, introduces several advanced features aimed at enhancing its capabilities, particularly with browser targeting, clipboard hijacking, and improved persistence mechanisms.

XCSSET is recognized as a modular malware designed to steal information and cryptocurrencies, with the ability to extract data from Notes and various cryptocurrency wallets, as well as browser histories from affected devices. Its propagation relies on detecting and infecting Xcode projects, which are commonly utilized by software developers. The malware executes during the building of infected projects, capitalizing on the collaborative nature of development work for Apple or macOS applications.

Microsoft’s analysis reveals significant updates in the new malware variant, especially in its data theft strategies. It now includes functionality to extract data from Firefox by utilizing a modified version of the open-source HackBrowserData tool. This enhancement allows the malware to decrypt and export valuable browser data stored by users.

Furthermore, the malware has evolved its clipboard hijacking capabilities. The update allows it to monitor the macOS clipboard for cryptocurrency address patterns. When it detects such an address, the malware seamlessly replaces it with one controlled by the attackers. Consequently, any cryptocurrency transactions initiated by the user on an infected device could be redirected to the attackers, potentially leading to significant financial losses.

In its quest for persistence, the new variant utilizes advanced techniques, such as creating LaunchDaemon entries that trigger a hidden payload and establishing a counterfeit System Settings.app in the /tmp directory. This deceptive maneuver aims to mask its malicious activities from users and security scrutiny.

Currently, this variant has not been widespread; Microsoft reports that its presence has only been noted in a handful of attacks. Researchers have promptly communicated their findings to Apple and are collaborating with GitHub to eliminate any associated repositories that may harbor the malware.

To mitigate risks associated with XCSSET and similar threats, users are urged to maintain updated versions of macOS and its applications. Microsoft emphasizes the importance of vigilance for developers, who should thoroughly inspect Xcode projects shared with them before proceeding with any builds, particularly as XCSSET has previously leveraged both zero-day vulnerabilities and other exploits in its operations.

Ticker Take Partners with NYSE to Enhance Financial Storytelling
NDP leadership candidate Rob Ashton apologizes for using AI-generated responses during campaign event
Opening-Up eWallets’ Future: The Enduring Value of eWallets in the Trading Space ︳FM Talks x Paysafe
World’s 10 Richest People Lose Nearly $70 Billion Amid Trade War Fears
American Bitcoin Plummets 20% After Nasdaq Launch
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article Erastus 2025 09 25T145006.490 1 1000x600 20 Million XRP Transfer Signals Potential Accumulation Amid Mixed Market Sentiment
Next Article news story Ripple’s RLUSD Stablecoin Now Listed on Bybit Exchange
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
image 2
Archax Launches Real-Time Streaming Cash Flows for Tokenized Securities on Hedera
urlhttps3A2F2Fg.foolcdn.com2Feditorial2Fimages2F8745522Fspcx stock ipo.jpgw1200opresize
SpaceX Goes Public with $2.1 Trillion Valuation After Strong IPO Debut
5a440778ac8f2b72736c872664e8a572
Insider Purchases 10,000 Shares of Phibro Animal Health Amidst Stock Decline
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Company
  • Finance
  • Stocks
  • Bitcoin
  • News
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?