logo

New XCSSET macOS malware variant used in limited attacks

ID: cf30f7e6-8204-5e03-ad06-ec1c249797f5

STIX ID: report--cf30f7e6-8204-5e03-ad06-ec1c249797f5

Feed Name: Security Affairs

Threat Score
65/100

Date Published: 2025-02-18

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Microsoft Threat Intelligence identified a new variant of the macOS XCSSET malware used in limited real-world attacks. The variant increases payload obfuscation by randomizing encoding methods (including Base64 and xxd), obfuscates module names, adds new persistence methods (creating zshrc launch files and replacing a Launchpad app), and introduces multiple mechanisms to implant payloads into Xcode projects; Microsoft Defender for Endpoint detects XCSSET and users are advised to verify Xcode projects and install apps only from trusted sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.