BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New XCSSET macOS Malware Variant Targets Firefox, Steals Crypto

XCSSET Malware Returns: New macOS Variant Targets Browsers, Cryptocurrency Wallets, and Developer Projects

  • Researchers found an updated variant of the XCSSET Malware targeting macOS systems.
  • The malware now includes new methods for browser targeting, clipboard monitoring, and persistence.
  • This version enhances encryption, uses stealthier AppleScripts, and collects data from Firefox browsers.
  • It can change copied cryptocurrency wallet addresses to redirect transactions to attacker-controlled wallets.
  • Users are advised to keep systems updated and be cautious with Xcode projects and clipboard content.

Researchers with the Microsoft Threat Intelligence team reported the discovery of a new variant of XCSSET, a sophisticated malware that targets Apple macOS. The malware, active in limited attacks, brings updates focusing on browser data theft, clipboard hijacking, and maintaining persistence on infected devices.

- Advertisement -

The updated XCSSET uses advanced encryption, obfuscation and run-only AppleScripts for stealth, according to Microsoft’s report published Thursday. It can now access and steal data from Mozilla Firefox browsers, and establishes persistence through LaunchDaemon entries, which help the malware stay active on a compromised system.

The new variant expands its data theft options and includes a clipper module that looks for cryptocurrency wallet addresses in the clipboard and swaps them with addresses controlled by attackers, Microsoft said. When users copy a cryptocurrency address, the malware detects this pattern and replaces it, aiming to redirect funds if a transaction occurs. The malware also uses a staged infection process, with the final stage involving an AppleScript app running commands to gather system information and activate modules via a function called boot().

Notable changes in this version include more checks for Firefox and modifications to detect the presence of the Telegram app. The malware’s structure now includes new modules: one for setting up LaunchDaemon (xmyyeqjx), another for Git-based persistence (jey), and a reworked information module that includes the clipboard hijacker (vexyeqj). It also uses a tool based on the open-source HackBrowserData project to extract Firefox data.

XCSSET targets Xcode projects—files used by developers to create macOS applications. While distribution methods are not fully known, sharing infected Xcode projects is believed to be the main route. Microsoft previously noted enhancements in XCSSET’s error handling and the use of multiple techniques to remain on a compromised host.

- Advertisement -

To reduce risk from XCSSET, experts recommend keeping operating systems up to date, carefully reviewing Xcode projects from third parties, and exercising care when copying sensitive cryptocurrency information.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin ETF Inflows Spark Hope After 2026 Price Lows

Bitcoin has plunged to 2026 lows of under $60,000, down 50% from its October...

Investors Bet on Onchain Credit Infrastructure Over DeFi

Morpho Labs raises $175M from investors like Paradigm, aiming to become a foundational credit...

Shiba Inu Recovery Stalls; Full Rebound Could Take Years

Shiba Inu has recovered 1.8% in the last day and 12.6% over the week...

US Orders Anthropic to Disable AI Models Citing Security

Anthropic disabled its most advanced AI models, Claude Fable 5 and Mythos 5, for...

Bitcoin’s Bear-Market Low Could Be Higher: Research

New research from Galaxy Digital suggests Bitcoin's bear market bottom could be higher than...

Must Read

How To Buy a Handshake Domain: A Step-by-Step Guide

Handshake Domains | Benefits | Drawbacks | How To Buy | Supported BrowsersIn this step-by-step guide, I am going to show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading