Microsoft: New Variant of macOS Threat XCSSET Spotted in the Wild
ID: c998b578-9f5f-5e7e-b59e-3ea6e16a6a20
STIX ID: report--c998b578-9f5f-5e7e-b59e-3ea6e16a6a20
Feed Name: Dark Reading
Date Published: 2025-02-18
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
Microsoft published analysis of an updated XCSSET macOS malware variant targeting Xcode developers: the variant adds stronger obfuscation, new persistence mechanisms (a ~/.zshrc_aliases method and a dock/Launchpad hijack via a signed dockutil), and multiple infection strategies that enable wormable supply-chain spread; it can exfiltrate data from Safari and apps (Skype, Telegram, WeChat, Notes), take screenshots, target digital wallets, and encrypt files, and defenders are advised to inspect downloaded Xcode projects and use Microsoft Defender for Endpoint.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
