
Security researchers have uncovered a new variant of the XCSSET malware targeting macOS users, with advanced capabilities designed to steal cryptocurrency and sensitive data while evading detection.
Microsoft’s threat intelligence team reported on Monday that they had identified this updated strain in limited attacks. XCSSET, originally discovered in August 2020, spreads through infected Xcode projects—Apple’s development environment for creating macOS and iOS applications.
The new variant introduces enhanced stealth techniques, allowing it to persist on infected devices and spread more efficiently. It continues to target cryptocurrency wallets, extract Notes app data, and exfiltrate system files.
Microsoft urged developers to carefully inspect any Xcode projects downloaded from third-party repositories and to install software only from trusted sources, such as official app stores.
The discovery comes amid a broader wave of malware campaigns aimed at cryptocurrency and fintech firms.
While no specific hacker group has been linked to these attacks, previous research has associated similar campaigns with state-sponsored North Korean cyber operations.
Cybersecurity experts advise organisations in cryptocurrency and fintech to implement strong endpoint security, monitor unusual network activity, and train employees to detect social engineering attacks.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543