Skip to main content
  1. Home
  2. Computing
  3. News

Updated macOS malware variant uncovered by Microsoft

Add as a preferred source on Google
A person using a laptop with a set of code seen on the display.
Sora Shimazaki / Pexels

Microsoft has observed a previously dormant macOS malware that has become active once again in a new variant that is targeting Apple devices of all kinds.

Microsoft Threat Intelligence shared information about the malware in a post on X, indicating that it is a new version of XCSSET that originated in 2022. The security experts explained that the updated malware has “enhanced obfuscation methods, updated persistence mechanisms, and new infection strategies.”

Recommended Videos

Microsoft Threat Intelligence has uncovered a new variant of XCSSET, a sophisticated modular macOS malware that targets users by infecting Xcode projects, in the wild. While we’re only seeing this new XCSSET variant in limited attacks at this time, we’re sharing this information… pic.twitter.com/oWfsIKxBzB

— Microsoft Threat Intelligence (@MsftSecIntel) February 17, 2025

TechRadar noted that the XCSSET malware is essentially an infostealer, with the ability to attack digital wallets, gather data from the Apple Notes app, and collect system information and files.

The malware is particularly dangerous because it uses infected projects in Apple’s Xcode platform to infiltrate devices. Xcode is the official integrated development environment (IDE) Apple provides for app creation for its various operating systems, including macOS, iOS, iPadOS, watchOS, and tvOS. The environment includes a code editor, debugger, Interface Builder, and tools for testing and deploying apps, the publication added.

As said, the updated XCSSET variant includes processes, allowing the malware to better obscure itself within Xcode. To do so, it uses two techniques, called “zshrc” and “dock”. The first attack allows the malware to create a file, ~/.zshrc_aliases, which holds the infected data. Then it adds a command in the ~/.zshrc file, which will prompt the infected file to launch every time a new shell session is initiated. This will ensure the malware will continue to spread with additional shell sessions.

With the second attack, the malware downloads “a signed dockutil tool from a command-and-control server to manage the dock items, ” Microsoft explained. After this, it creates a fake Launchpad app to replace the path entry for the actual Launchpad app on the device dock. When a user runs Launchpad on an infected device, the actual Launchpad app and the malware version will both execute, effectively spreading XCSSET.

Microsoft Threat Intelligence explained it has only seen the new malware variant “in limited attacks,” it is sharing information about the threat so users and organizations can take precautionary measures.

Fionna Agomuoh
Fionna Agomuoh is a Computing Writer at Digital Trends. She covers a range of topics in the computing space, including…
Satechis’s color-matched MacBook Neo accessories are just too pretty to ignore
If you wish Apple made peppy accessories for its budget laptop, Satechi heard your prayers without charging you a bomb for it.
Satechi MacBook Neo accessories

Satechi, which makes some fantastic charging and PC peripherals, has just launched a whole bunch of accessories targeted at the MacBook Neo. But instead of making them boring and drab, the company has actually color-matched them to the exact shade that you get on Apple's budget-centric laptop. The offerings on the table include a multi-port adapter, a USB-C snap hub, and a wireless mouse, and all of them are now available to buy starting at $29.99 from Satechi's website and Amazon. Color options that are up for grabs include Citrus, Blush, Indigo, and Silver

Satechi OntheGo 5-in-1 Multiport Adapter ($44.99)

Read more
ChatGPT’s hiking advice left two hikers stranded on a mountain in Poland
The chatbot directed the pair onto a climbing route neither had the skills to finish, and it's not the first time AI has sent travelers somewhere they shouldn't have gone.
Bag, Clothing, Coat

A shortcut recommended by ChatGPT left two hikers stuck on a mountain face in Poland this month, and they needed a helicopter to get back down. It's the latest case of an AI chatbot steering travelers toward routes it has no real way to evaluate.

ChatGPT's shortcut led straight to a dead end

Read more
Firefox is doubling its update pace, and that’s good news for your security
Mozilla Firefox

Mozilla is about to speed up one of the most important parts of using Firefox: security updates. If you're used to seeing a new Firefox update land about once a month, that's about to change. Beginning in September, Mozilla plans to switch to a two-week release schedule for Firefox on desktop and Android, meaning users should start getting updates twice as often. That might sound like more frequent downloads, but it's really about closing security gaps sooner.

Why waiting a month for security fixes no longer cuts it

Read more