Updated macOS malware variant uncovered by Microsoft

Microsoft has observed a previously dormant macOS malware that has become active once again in a new variant that is targeting Apple devices of all kinds.

Microsoft Threat Intelligence shared information about the malware in a post on X, indicating that it is a new version of XCSSET that originated in 2022. The security experts explained that the updated malware has “enhanced obfuscation methods, updated persistence mechanisms, and new infection strategies.”

Recommended Videos

Microsoft Threat Intelligence has uncovered a new variant of XCSSET, a sophisticated modular macOS malware that targets users by infecting Xcode projects, in the wild. While we’re only seeing this new XCSSET variant in limited attacks at this time, we’re sharing this information… pic.twitter.com/oWfsIKxBzB

— Microsoft Threat Intelligence (@MsftSecIntel) February 17, 2025

TechRadar noted that the XCSSET malware is essentially an infostealer, with the ability to attack digital wallets, gather data from the Apple Notes app, and collect system information and files.

The malware is particularly dangerous because it uses infected projects in Apple’s Xcode platform to infiltrate devices. Xcode is the official integrated development environment (IDE) Apple provides for app creation for its various operating systems, including macOS, iOS, iPadOS, watchOS, and tvOS. The environment includes a code editor, debugger, Interface Builder, and tools for testing and deploying apps, the publication added.

As said, the updated XCSSET variant includes processes, allowing the malware to better obscure itself within Xcode. To do so, it uses two techniques, called “zshrc” and “dock”. The first attack allows the malware to create a file, ~/.zshrc_aliases, which holds the infected data. Then it adds a command in the ~/.zshrc file, which will prompt the infected file to launch every time a new shell session is initiated. This will ensure the malware will continue to spread with additional shell sessions.

With the second attack, the malware downloads “a signed dockutil tool from a command-and-control server to manage the dock items, ” Microsoft explained. After this, it creates a fake Launchpad app to replace the path entry for the actual Launchpad app on the device dock. When a user runs Launchpad on an infected device, the actual Launchpad app and the malware version will both execute, effectively spreading XCSSET.

Microsoft Threat Intelligence explained it has only seen the new malware variant “in limited attacks,” it is sharing information about the threat so users and organizations can take precautionary measures.

Editors’ Recommendations

  • Microsoft is making a major change to using your iPhone in Windows

  • Microsoft Outlook has a new ‘critical’ flaw that spreads malware easily

  • Microsoft warns that the latest Windows 11 update may crash PC games now

  • I found an app that fixes macOS Sequoia’s annoying pop-ups

  • macOS Sequoia fixes a problem that’s bugged me for years




Related posts

Latest posts

Dell Tech Days: Big Savings on AI-Ready PCs and More

Dell / Dell Good news if you’ve been waiting for the right time to , Dell Tech Days is offering deals that make waiting worth it. on top PCs, monitors, and accessories, plus 2x Dell Rewards. Pull the trigger and get yourself an AI-ready machine and score big on premium hardware. Savings on Products Recommended […]

I tried roaming on Google Fi and T-Mobile, this is the best

If you travel abroad frequently, you’ve probably wondered how to cut back on bill shock. We’ve all been there: you have a great vacation, get back home, and your next postpaid bill drops. Except, it’s much higher than you expected thanks to roaming charges for using your phone abroad. Most networks offer some form of […]

Research suggests cutting down screen time can work better than antidepressants

With access to internet cut off, screen time came crashing down, leading to better mental health, improved sleep, and positive behavioral changes in users.

Google makes it harder to accidentally call 911 with your Pixel Watch

A new feature will help reduce the number of accidental 911 calls from Pixel Watches, and it's rolling out to Pixel Watch users now.

Google’s new policy tracks all your devices with no opt-out

Google has implemented the same strategy they once called wrong and subverts user choice. The tracking has begun and it's happening without your permission.

Amazon is replacing its TikTok-like Inspire with Rufus the AI bot

Amazon shut down Inspire and will be replacing it with AI shopping assistant, Rufus.

This Lenovo ThinkPad is normally $3,229 — today it’s $1,453

The Lenovo ThinkPad X1 Carbon Gen 11 provides reliable performance from a portable body. The laptop is on sale from Lenovo at 55% off, or savings of $1,776.

Meta’s new ‘Llamacon’ event is all about open-source AI

Meta Connect returns in September but will be preceded by the new Llamacon AI conference in April.

Chase’s latest move will help cut fraud, but Zelle users may not like it

Chase Bank will be blocking Zelle payments to sellers on social media platforms and messaging apps starting March 23.

The Alienware x16 R2 gaming laptop with RTX 4070 is $845 off

The Alienware x16 R2 gaming laptop with the Nvidia GeForce RTX 4070 graphics card and 32GB of RAM is on sale from Dell with an $845 discount, down to $2,100.