Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

The Rise of Wish.com: How $10 billion e-commerce unicorn crashes and burns

Top AI Companies to Invest In

Adobe releases patches, fixes 254 vulnerabilities, closes high-strength security gaps

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Microsoft discovers new XCSSET MACOS malware variants with advanced obfuscation tactics
Identity

Microsoft discovers new XCSSET MACOS malware variants with advanced obfuscation tactics

userBy userFebruary 17, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

February 17, 2025Ravi LakshmananEndpoint Security/Malware

XCSSET MACOS Malware

Microsoft said it has discovered a new variant of the known Apple MacOS malware called Xcsset as part of a limited attack in the wild.

“This latest XCSSet malware, the first known variant since 2022, features obfuscation methods, updated persistence mechanisms, and new infection strategies,” the Microsoft Threat Intelligence team said in a shared post for X. It is stated in.

“These enhanced features add to the previously known features of this malware family, including targeting digital wallets, collecting data from the Notes app, and removing system information and files.”

Cybersecurity

XCSSet is a sophisticated modular MACOS malware known to target users by infecting Apple Xcode projects. It was first recorded in August 2020 by Trend Micro.

Subsequent iterations of malware have been found to adapt to compromise on newer versions of MacOS, as well as Apple’s own M1 chipset. In mid-2021, cybersecurity companies noted that XCSSET was updated to remove data from various apps such as Google Chrome, Telegram, Evernote, Opera, Skype, WeChat and Apple’s first-party apps.

Another report from JAMF shows the ability, transparency, consent, and control (TCC) framework bypass bug to leverage CVE-2021-30713, and the victim’s desktop screen without the need for additional permission It has revealed that bypassing the bug as a zero day to take shots. .

Then, over a year later, it was updated again to add support for Macos Monterey. At the time of writing, the origin of the malware remains unknown.

The latest findings from Microsoft show the first major revision since 2022, and new shell sessions using improved obfuscation methods and persistence mechanisms aimed at challenging analytical efforts guarantees that malware will start every time it is started.

Cybersecurity

Another novel etiquette that XCSSET sets involves downloading a signed Dockutil utility from the command and control server to manage dock items.

“The malware then creates a fake LaunchPad application and replaces the legitimate LaunchPad path entry in the dock with this fake,” Microsoft said. “This ensures that each time Launchpad starts from the dock, both a legal Launchpad and a malicious payload will be performed.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleWhich countries are top military spenders and where does Europe rank? |Military News
Next Article Trump fires hundreds of air traffic support staff when SpaceX visits the FAA Command Center
user
  • Website

Related Posts

Adobe releases patches, fixes 254 vulnerabilities, closes high-strength security gaps

June 10, 2025

Researchers have discovered over 20 composition risks, including five CVEs, in the Salesforce industry cloud

June 10, 2025

Fin6 delivers More_Eggs malware using fake resumes on AWS hosts on LinkedIn

June 10, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

The Rise of Wish.com: How $10 billion e-commerce unicorn crashes and burns

Top AI Companies to Invest In

Adobe releases patches, fixes 254 vulnerabilities, closes high-strength security gaps

Researchers have discovered over 20 composition risks, including five CVEs, in the Salesforce industry cloud

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

The Rise of Wish.com: How $10 billion e-commerce unicorn crashes and burns

Top AI Companies to Invest In

Enterprise Search Startup Green valuates $7.2 billion in Series F funding for $150 million

Linear raises $82 million at a $1.25 billion valuation in Series C funding to challenge Atlassian

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.