Bitcoin Forum
May 26, 2024, 12:15:03 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: XCSSET Malware: Leveraging Xcode projects to insert Malware  (Read 90 times)
cryptomaniac_xxx (OP)
Hero Member
*****
Offline Offline

Activity: 1512
Merit: 567


View Profile
August 15, 2020, 09:04:28 AM
 #1

A new form of Mac malware called XCSSET is slowly getting its way thru Xcode, which is a IDE used in MacOS to developed Apple-related softwares and freely available. So if you are a MacOS developer, you need to be very careful and read this.


Quote

"Presumably, these systems would be primarily used by developers," the team noted. "These Xcode projects have been modified such that upon building, these projects would run a malicious code. This eventually leads to the main XCSSET malware being dropped and run on the affected system."

Below is a summary of the routines we have identified:

• Manipulates browser results
Manipulates and replace found bitcoin and other cryptocurrency addresses
• Replaces the Chrome download link with a link to an old version package
• Steals Google, Yandex, Amocrm, SIPmarket, Paypal, and Apple ID credentials
• Steals credit card data linked in the Apple Store
• Prevents the user from changing password but can also record the new password if it is changed
• Takes screenshots of certain accessed sites


You can read the paper here: https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!