A new variant of the XCSSET malware has been discovered, targeting macOS users with enhanced capabilities and evasion techniques. This malware primarily spreads through compromised Xcode projects and malicious websites, aiming to steal sensitive information and deploy additional payloads. The latest variant includes improvements such as better obfuscation, the ability to bypass security measures, and expanded data exfiltration methods. Researchers have noted that this malware targets developers by injecting malicious code into Xcode projects, which then infects the compiled applications. The infection chain often begins with phishing campaigns or compromised websites that lure victims into downloading infected projects. Once executed, the malware can steal browser cookies, credentials, and other sensitive data, posing significant risks to users and organizations relying on macOS environments. Security experts recommend updating software regularly, avoiding untrusted downloads, and employing robust endpoint protection to mitigate the threat. This discovery highlights the evolving tactics of cybercriminals targeting Apple ecosystems and underscores the importance of vigilance and proactive defense strategies in cybersecurity.
This Cyber News was published on cybersecuritynews.com. Publication date: Fri, 26 Sep 2025 13:15:17 +0000