
#Wechat for mac virus mac
How can Mac users avoid XCSSET infection? The malware downloads packages from its own command and control server that come pre-signed with ad-hoc signatures to launch these fake apps.įor more technical analysis of this malware, you can refer to Trend Micro’s blog and technical brief. The updated XCSSET malware has adapted to the newly released Big Sur (MacOS 11) and can circumvent its new security policies. XCSSET malware has a critical set of ransomware modules that most often remain inactive, but if a victim is deemed to be a good target for extorsion, they have the potential of executing. Investigations have revealed that stolen information mainly came from China, closely followed by India, but many people from the United States, Ukraine, Pakistan, and the Philippines have been affected, too.

It can also collect credit card and Apple ID information linked to the Apple App Store and steal credentials from Google Chrome, Yandex, PayPal, and other platforms.Īdditionally, it can access user data from apps such as QQ, WeChat, Telegram, and Skype, while also controlling their security and privacy settings.

It can also take screenshots of the victim’s desktop and hijack their web browser. This allows hackers to manipulate and replace Bitcoin (BTC), Ethereum (ETH), Tether (USDT), and other cryptocurrency addresses. It also exploits the browser debugging mode of Chrome-based browsers.

Steals information from apps and Chrome-based browsers
