Macs under attack from dangerous malware targeting digital wallets and Apple’s Notes app — how to stay safe

MacBook Pro 2021 (16-inch) on a patio table
(Image credit: Tom's Guide)

Despite what you may want to believe, your Mac isn’t malware-proof and it might be more susceptible to a nasty malware infection now that hackers have set their sights on Apple’s computers.

As reported by BleepingComputer, a new variant of the modular Mac malware XCSSET has been discovered in the wild. And with several updates under the hood it’s now better at hiding in plain sight, establishing persistence on the best MacBooks and using Apple’s own tools to infect unsuspecting users.

In a post on X, Microsoft’s Threat Intelligence team explains that they identified this new variant in limited attacks. Still, it could be used to steal money from any digital wallet or crypto apps on your Mac and it’s also capable of exfiltrating data from Apple’s Notes app.

Here’s everything you need to know about this updated Mac malware variant along with some tips and tricks on how you can keep your Apple computer safe from viruses and hackers.

Hiding in Launchpad

All of the apps on my MacBook Pro

(Image credit: Apple)

First discovered back in 2020, the XCSSET malware hasn’t received a major update since 2022. Now though, this new variant features better obfuscation to help it hide on infected Macs, two persistence techniques to help it remain on infected machines and new infection methods using Apple’s Xcode.

For those unfamiliar, Xcode is a developer toolset used for creating, testing and distributing apps across all of Apple’s various platforms. Developers can build their own Xcode projects from scratch or do so using resources from other repositories.

By upgrading XCSSET to use Xcode as an infection method, the cybercriminals behind it have upgraded the malware’s reach significantly. For instance, it could be used to create malicious Mac apps which would then be distributed via Apple’s Mac App Store.

In its warning, Microsoft’s security researchers explained that once installed on a vulnerable Mac, XCSSET creates a malicious Launchpad app and changes the real app’s path to point to this fake one. As such, when you use Launchpad to find, launch and switch between apps on your Mac, the malicious payload inside the malware is executed.

From there, XCSEET can be used to steal funds from your digital wallet apps as well as to steal any sensitive data you’ve stored in Apple’s own Notes app.

How to stay safe from Mac malware

A padlock resting next to the Apple logo on the lid of a gold-colored Apple laptop.

(Image credit: robert coolen/Shutterstock)

If you’re not a developer (and chances are you aren’t) you shouldn’t be installing any apps on your Mac as Xcode projects. Instead, you should only install new apps on your Mac from trusted sources. If you want to be extra safe, you may want to consider only installing new apps from the Mac App Store as just like on iOS, all of the apps hosted on this official store go through rigorous security checks.

While your Mac does come with built-in security software in the form of XProtect, you may also want to consider using one of the best Mac antivirus software solutions alongside it. These paid Mac antivirus offerings are regularly updated and many include useful extras like a password manager or a VPN to help keep you and your data safer online.

It’s also worth noting that you shouldn’t install any apps that are recommended to you via email, texts or social media messages. Hackers can easily take over the accounts of your friends and family and then use them in phishing attacks where they might suggest an app you should try out and provide a link to it.

Going after Apple devices and especially Macs has proved to be quite profitable for cybercriminals and hackers, so I don’t expect this threat to die down anytime soon. That’s why it’s up to you to keep your devices updated, limit the number of apps installed on them and to be extremely careful when downloading and installing any new software.

More from Tom's Guide

Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
Malware
New macOS malware uses Apple's own code to quietly steal credentials and personal data — how to stay safe
MacBook Pro 2021 (16-inch) on a patio table
Millions of Mac owners urged to be on alert for info-stealing malware
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
MacBook Pro 2023
Macs under attack from North Korean malware stealing passwords and more — how to stay safe
MacBook Pro 16-inch 2021 sitting on a patio table
Critical macOS flaw puts your data and cameras at risk — update right now
One phone with skull and crossbones on screen among several other clean-looking phones.
Malicious iPhone apps are spreading screenshot-reading malware on the Apple App Store — how to stay safe
Latest in Online Security
A picture of a skull and bones on a smartphone depicting malware
Hundreds of malicious Android apps with 60 million downloads found spamming Android users with ads and stealing credentials
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
An FBI agent typing on a computer
FBI issues warning to millions of Americans to avoid these websites that can steal your passwords and banking info
A hacker typing quickly on a keyboard
New MassJacker malware is hijacking digital wallets to steal large sums from users
iPhone 15 Pro Max shown in hand
5 iPhone settings you should always shut off — because they’re a security nightmare
A woman using her laptop securely with a cup of coffee in hand
5 common mistakes people make when shopping for antivirus software
Latest in News
NYTimes Connections
NYT Connections today hints and answers — Wednesday, March 19 (#647)
Chromecast with Google TV connected to display
Google finally pushes out full Chromecast fix for users who factory reset — here’s what to do
A picture of a skull and bones on a smartphone depicting malware
Hundreds of malicious Android apps with 60 million downloads found spamming Android users with ads and stealing credentials
Switch 2 console and logo
Nintendo Switch 2 rumor just tipped possible release date — and it's much sooner than we thought
Hacker typing on laptop in darkened room
Hackers create "BRUTED" tool to attack VPNs – how to stay safe
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs