Microsoft discovers a variant of malware XCSSET targeting encrypted wallets
ChainCatcher news, according to Decrypt, researchers from Microsoft Threat Intelligence have discovered a new type of malware that can target cryptocurrency wallets. XCSSET was first identified in 2020, allowing malicious actors to take screenshots, record user behavior, and steal data from Telegram. The updated version can also locate data within the Apple Notes application and uses obfuscation techniques to make the malware harder to detect. XCSSET theoretically also has the capability to manipulate what the end user sees in their browser. This could include modifying or replacing Bitcoin and other cryptocurrency addresses, meaning funds may not be sent to their intended destination.
Researchers added that users must always check and verify any Xcode projects downloaded or cloned from repositories, as malware often spreads through infected projects. They should also only install applications from trusted sources, such as the official app stores of software platforms.