Ethical Hacking News
A new variant of the macOS malware XCSSET has been uncovered by Microsoft Threat Intelligence researchers. This targeted attack is believed to be limited in scope, but its ability to steal sensitive information from target systems and launch ransomware attacks makes it a serious concern for users. With its use of encryption and obfuscation techniques, this variant avoids detection by security software, highlighting the need for increased vigilance among cybersecurity professionals.
Microsoft researchers have discovered a new variant of macOS malware known as XCSSET.The new variant is targeted towards specific individuals or organizations, suggesting limited attacks.The malware features a submodule to monitor the clipboard and download configuration files with address regex patterns associated with digital wallets.XCSSET can substitute clipboard content with its own predefined wallet addresses if a pattern match is detected.The malware includes an info-stealer module that exfiltrates data stored by Firefox, including passwords, history, and credit card information.The new variant has four stages of infection, including boot() function calls to download and run submodules.Submodules like vexyeqj (info-stealer), bnk (payload), and jey (obfuscation/persistence) work together to achieve the malware's objectives.MICROSOFT warns users about the importance of keeping their systems updated, using reputable security software, and being cautious with public Wi-Fi networks and suspicious links.
Microsoft Threat Intelligence researchers have recently uncovered a new variant of the macOS malware known as XCSSET. This particular variant has been employed in limited attacks, suggesting that it is likely targeted towards specific individuals or organizations.
The researchers discovered the new XCSSET variant through their monitoring of threat intelligence data and analysis of various security-related reports. They found that this new variant features a submodule designed to monitor the clipboard and references a downloaded configuration file containing address regex patterns associated with various digital wallets.
If a pattern match is detected, XCSSET is capable of substituting the clipboard content with its own predefined set of wallet addresses. The updated stage also downloads and runs several new modules, extending the malware's functionality compared with the older variant.
One of these new modules is an info-stealer module designed to exfiltrate data stored by Firefox. This module appears to be a modified version of a GitHub project called HackBrowserData, which is capable of decrypting and exporting browser data stored by browsers. Passwords, history, credit card information, and cookies are some of the key information it can extract from almost all popular browsers.
The new XCSSET variant implements a four-stage infection chain. The initial three stages are consistent with previous variants. Microsoft detailed the fourth stage, which includes the boot() function and its associated calls to download and run submodules.
The new XCSSET variant includes several focused submodules, including vexyeqj (info-stealer), bnk (payload), neq_cdyd_ilvcmwx (file-stealer), xmyyeqjx (LaunchDaemon persistence), jey (obfuscation/persistence), and iewmilh_cdyd (Firefox stealer).
These submodules work together to achieve the malware's primary objectives, which include stealing sensitive information from target systems and launching ransomware attacks. The new XCSSET variant uses encryption and obfuscation techniques to avoid detection by security software.
Microsoft has warned users of the importance of keeping their operating systems and applications up-to-date and using reputable security software to protect against such targeted attacks. Users should also be cautious when using public Wi-Fi networks or clicking on suspicious links, as these can also expose them to malware infections.
In addition to warning users about the new XCSSET variant, Microsoft has also called for increased vigilance among cybersecurity professionals in order to better understand and address the evolving threat landscape.
Related Information:
https://www.ethicalhackingnews.com/articles/New-Variant-of-XCSSET-macOS-Malware-Uncovered-A-Targeted-Attack-on-Apple-Devices-ehn.shtml
https://securityaffairs.com/182662/malware/microsoft-uncovers-new-variant-of-xcsset-macos-malware-in-targeted-attacks.html
https://www.microsoft.com/en-us/security/blog/2025/03/11/new-xcsset-malware-adds-new-obfuscation-persistence-techniques-to-infect-xcode-projects/
Published: Sat Sep 27 00:52:59 2025 by llama3.2 3B Q4_K_M