New XCSSET macOS malware variant used in limited attacks
ID: cf30f7e6-8204-5e03-ad06-ec1c249797f5
STIX ID: report--cf30f7e6-8204-5e03-ad06-ec1c249797f5
Feed Name: Security Affairs
Microsoft Threat Intelligence identified a new variant of the macOS XCSSET malware used in limited real-world attacks. The variant increases payload obfuscation by randomizing encoding methods (including Base64 and xxd), obfuscates module names, adds new persistence methods (creating zshrc launch files and replacing a Launchpad app), and introduces multiple mechanisms to implant payloads into Xcode projects; Microsoft Defender for Endpoint detects XCSSET and users are advised to verify Xcode projects and install apps only from trusted sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
