Third macOS Zero-Day Attack Takes Advantage through Safari

Macos Zero Day Attack Featured

There was a time when Macs were considered safe from malware and other ills. Attackers preferred to go after Windows users simply because there were more of them – attackers could get more bang for their buck. That’s been changing, however, with more people owning Macs. This has led to a third zero-day attack on macOS in less than a year, allowing attackers to take advantage in several ways through Safari.

Discovery of Third macOS Zero-Day Attack

Last August, security experts found XCSSET, a zero-day attack that affected Mac developers. It gave them access to browser cookies and files. It also left behind website backdoors and made off with information from applications while leaving behind a ransom note. This past March, SentinelOne researchers discovered a library of Trojan code that installed the XCSSET malware on developer Macs.

A third instance of XCSSET has been discovered by Trend Micro researchers. In these two zero-day attacks on macOS, one takes advantage of a flaw to steal cookies, and the other takes advantage of a developer edition of Safari. The researchers found the attacks to be “quite unusual.”

Macos Zero Day Attack Malware

“Malicious code is injected into local Xcode projects so that when the project is built, the malicious code is run. This poses a risk for Xcode developers in particular. The threat escalates since we have identified affected developers who shared their projects on GitHub, leading to a supply-chain-like attack for users who rely on these repositories as dependencies in their own projects,” reads a blog post on the Trend Micro website. The researchers believe the attacks could be widespread, as the malware was also identified on VirusTotal sources.

The researchers detected the entry threat as “TrojanSpy.MacOS.XCSSET.A and its command and control (C&C) related files as Backdoor.MacOS.XCSSET.A.”

The Harm that XCSSET Causes

X code projects and modified apps are created from the malware and spread the attack. What isn’t known is how the malware reaches these Macs. What is known is that the X code projects have been modified to run malicious code, which reaches the Macs, leading user credentials and other information to be stolen.

Once it lands on a system, XCSSET can:

  • Abuse Safari and other browsers
  • Read and dump Safari cookies
  • Inject backdoors on the Safari development version through a UXSS attack
  • Steal information from apps
  • Take screenshots
  • Upload user files to the attacker’s server
  • Encrypt files
  • Show a ransom note
Macos Zero Day Attack Laptop

A UXSS attack affects browsing primarily. It can:

  • Modify websites
  • Modify/replace Bitcoin and cryptocurrency addresses
  • Steal account credentials
  • Steal Apple Store credit card information
  • Block the user from changing passwords while stealing modified passwords
  • Take screenshots

With three occurrences of the Mac zero-day attack in less than a year, there’s no telling where and when it will hit next. Trend Micro suggests users only download apps from official, legitimate sources and use a multilayer security solution.

Read on to learn some ugly truths about zero-day exploits and whether Windows Defender is good enough in 2021.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Laura Tucker Avatar

Read next

Octopuses possess roughly 500 million neurons distributed across their body, with two-thirds located in their arms rather than their central brain, meaning each arm can taste, problem-solve, and react to stimuli independently of whatever the octopus is otherwise paying attention to.
The Roman aqueduct at Segovia, built around the first century AD without mortar, still carried water into the 1970s, its 167 granite arches held together by nothing but the precise weight distribution of stones cut to fit each other within fractions of a millimeter.
When the SS Great Eastern laid the first working transatlantic telegraph cable in 1866, a message that had taken ten days by steamship suddenly crossed the ocean in minutes, and the financial markets of London and New York were forced, within a single trading week, to invent the modern concept of synchronised global price.
The Big Ear telescope was scanning at 1420.4056 megahertz on the night of 15 August 1977, the exact frequency at which hydrogen atoms vibrate across the universe, because Giuseppe Cocconi and Philip Morrison had argued years earlier that any species trying to be found would broadcast on that channel — and then, for 72 seconds, something did.
In 2016, archaeologists dated two rings of snapped stalagmites in France’s Bruniquel Cave to 176,500 years ago, evidence that Neanderthals had walked 336 metres into darkness with fire and built architecture deep underground long before modern humans reached Europe
Otto von Bismarck was 74 when Germany adopted the world’s first national old-age social insurance program in 1889, setting the pension age at 70 after years of fighting socialists with bans, laws, and a promise few workers would live long enough to use
When cosmonaut Valeri Polyakov stepped out of his Soyuz capsule in March 1995 after 437 consecutive days aboard Mir, doctors recorded him at several centimetres above his pre-flight height, and his spine had become so unaccustomed to gravity that the recovery team carried him to a chair rather than risk the compression of letting him walk.
When Bell Labs engineer Karl Jansky pointed a rotating antenna at the sky in 1932 looking for sources of transatlantic radio static, he kept picking up a faint hiss that peaked every 23 hours and 56 minutes, and he eventually realized he had become the first human to hear the center of the Milky Way.