• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Updated XCSSET macOS Malware Introduces Enhanced Targeting and Data Exfiltration Techniques
Share
  • bitcoinBitcoin(BTC)$65,791.00
  • ethereumEthereum(ETH)$1,720.08
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$617.50
  • usd-coinUSDC(USDC)$1.00
  • rippleXRP(XRP)$1.19
  • solanaSolana(SOL)$71.10
  • tronTRON(TRX)$0.320412
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02
  • HyperliquidHyperliquid(HYPE)$64.83
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
News

Updated XCSSET macOS Malware Introduces Enhanced Targeting and Data Exfiltration Techniques

News Desk
Last updated: September 26, 2025 5:22 pm
News Desk
Published: September 26, 2025
Share
macos

Cybersecurity researchers have recently identified an updated variant of the notorious XCSSET malware, specifically targeting macOS systems. This new iteration has sparked concern within the cybersecurity community due to its refined techniques and expanded capabilities, particularly concerning browser security, clipboard hijacking, and enhanced mechanisms for persistence.

According to a report released by the Microsoft Threat Intelligence team, the updated XCSSET resembles a sophisticated modular malware that primarily infects Xcode projects used by software developers. Although the exact distribution method remains unclear, it is believed that the malware propagates through shared Xcode project files among developers working on macOS applications.

The latest variant significantly enhances its previous functionality by employing advanced encryption and obfuscation techniques to evade detection. It also utilizes run-only compiled AppleScripts for stealth execution, thereby enhancing its security against cybersecurity measures. Notably, this revision broadens its data extraction capabilities to include sensitive information from the Firefox browser, indicating a strategic pivot in its targeting approach.

A particularly alarming feature of the newfound variant is its integration of a clipper sub-module. This component is designed to monitor the clipboard for specific patterns that align with cryptocurrency wallet addresses. When a match is detected, the malware replaces the legitimate wallet address in the clipboard with an address controlled by the attackers, effectively rerouting transactions and potentially leading to significant financial losses.

The Microsoft report elaborated on further modifications in the malware’s infection chain. Among these, the fourth stage now involves an AppleScript application that executes a shell command to retrieve additional AppleScripts responsible for gathering system information. This implementation adds layers of complexity to its operations.

Additional noteworthy changes include enhanced checks for the Mozilla Firefox browser and a refined logic for detecting the presence of the Telegram messaging app. The latest version also features new modules that replace earlier iterations. For instance, the module previously known as “seizecj” has been rebranded as “vexyeqj,” which efficiently downloads another module named “bnk.” This module is run using AppleScript and incorporates functions for data validation, encryption, decryption, and fetching additional commands from a command-and-control (C2) server, alongside the clipper functionality.

Other modules introduced in this update include “neq_cdyd_ilvcmwx,” which is similar to a previous variant that exfiltrates files to the C2 server, and “xmyyeqjx,” which establishes persistence through LaunchDaemon. Furthermore, the “jey” module facilitates Git-based persistence, while “iewmilh_cdyd” is designed to harvest data from Firefox using a modified version of an openly available tool known as HackBrowserData.

In light of these developments, cybersecurity experts urge macOS users to regularly update their systems and remain vigilant when scrutinizing Xcode projects sourced from repositories or third-party locations. They also recommend exercising caution when copying and pasting sensitive information to prevent potential exploitation by this evolved malware.

AI Job Losses Could Trigger Stock Market Crash Concerns
Salesforce Faces Challenges Amid AI Disruption, But Stock May Be Attractively Priced For Future Growth
Treasury Department Cancels $21 Million in Contracts with Booz Allen After IRS Data Leak
XRP Price Holds Key Support Amidst Rising Bullish Momentum
Mercedes-Benz to Pay $149.6 Million to Settle Emission Test Cheating Allegations
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article Featured Image 1280x720 PRPartnered 2025 09 26T224910.558 Cloud Mining: A Game Changer for Earning Cryptocurrency
Next Article bitcoin cash cryptocurrency mining blockchain invest getty large Trump Family Reaps $5 Billion from World Liberty Crypto Venture Amid Ohio’s Move to Accept Cryptocurrency for State Payments
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
https2F2Fmedia.zenfs .com2Fen2Fstocktwits 3832Faf78dbdbcde1cf08e3cd57743e317625
Rocket Lab Prepares for Launch Blitz as it Joins Nasdaq-100
2e2ea7bf81bbad117e0709fb8135b6623cdc8111 1500x996
Bitcoin Soars to Two-Week High After US-Iran Deal Reopens Strait of Hormuz
liquidity in crypto bitcoin liquidation explained in 2026 800x420
$21 Million in Bitcoin Liquidations Trigger Massive Market Impact in Just Five Minutes
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Company
  • Finance
  • Stocks
  • Bitcoin
  • News
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?