last week,Trend MicroSecurity researchers have discovered a serious new macOS malware that uses zero-day vulnerabilities to abnormally infect Xcode-related development projects. Now security researchers have further revealed more relevant details about this new malware. It may even escape the detection of Apple’s review team and penetrate into the Mac’s App Store. The impact cannot be ignored.

Security personnel discovered that Mac applications were implanted with XCSSET malware, which may evade security detection and penetrate the App Store
This new type of malware is a member of the XCSSET family. What makes it unique is that it is embedded into Xcode and starts running malicious code during the developer’s project construction phase, just like the ubiquitous gopher hiding in the garden soil. The discovery poses a huge risk to Xcode developers, as security researchers examine developers affected by the malware who share their projects through GitHub, making other users who rely on their own projects also vulnerable to potential supply chain attacks.

The malware is spread via infected Xcode projects because it can create maliciously modified applications and then deliver the Trojan horse. Specifically, it can abuse Safari and other browsers to steal data, exploit vulnerabilities to read and dump cookies, use Javascript to build backdoors into the system and then modify displayed websites, steal private banking information, prevent password changes, and steal newly changed passwords. In addition, security personnel also discovered that this malicious program can steal messages and screenshots from applications such as Evernote, Notes, Skype, Telegram, QQ and WeChat, upload files to the attacker’s designated server, or encrypt and lock files and display ransom notes. What makes this malware particularly dangerous is that currently commonly used verification methods (such as checking hashes) cannot identify the infection, and the developers are not aware that they are distributing the malware.

After further research, security researchers Oleksandr Shatkivskyi and Vlad Felenuik believe that the macOS App Store review team will most likely not be able to detect applications containing XCSSET malicious code. Since the security researchers did not have access to test the Mac Developer tool that comes with Apple Silicon, they believe that the malware will work on Mac devices equipped with Apple Silicon. Despite the seriousness of the XCSSET malware, they still believe macOS is a safe operating system and are optimistic about the future of fighting malware.

In order to ensure the safety of computer use, you must abide by the basic principles, pay attention to the content running on macOS devices, do not use risky pirated or cracked software for cheap, and be the first line of defense for your own information security. If you have a lot of highly confidential information on your work computer, you should be more cautious and not allow any application to record your screen.
◎Data source:MacRumors (1)、MacRumors (2)、Trend Micro
Source: KOCPC Chinese