I have been crucified with Christ and I no longer live, but Christ lives in me. The life I now live in the body, I live by faith in the Son of God, who loved meand gave himself for me.
Gal 2:20
@ruffydfire He is a 100% complete hypocrite!. The things he spoke against he is doing them. He has no integrity in him. Disgrace is coming his way. That's the inevitability to his end.
Microsoft Threat Intelligence has uncovered a new variant of XCSSET, a sophisticated modular macOS malware that targets users by infecting Xcode projects, in the wild. While we’re only seeing this new XCSSET variant in limited attacks at this time, we’re sharing this information so users and organizations can protect themselves against this threat.
Its first known variant since 2022, this latest XCSSET malware features enhanced obfuscation methods, updated persistence mechanisms, and new infection strategies. These enhanced features add to this malware family’s previously known capabilities, like targeting digital wallets, collecting data from the Notes app, and exfiltrating system information and files.
Enhanced obfuscation methods: The new XCSSET variant uses a significantly more randomized approach for generating payloads to infect Xcode projects. Both its encoding technique and number of encoding iterations are randomized. In addition, while older XCSSET variants only used xxd (hexdump) for encoding, the latest one also incorporates Base64. At its code level, the variant’s module names are also obfuscated, making it more challenging to determine the modules’ intent.
Updated persistence mechanisms: The new XCSSET variant employs two distinct techniques: the “zshrc” method and the “dock” method. In the zshrc method, the malware creates a file named ~/.zshrc_aliases, which contains the payload. It then appends a command in the ~/.zshrc file to ensure that the created file is launched every time a new shell session is initiated, guaranteeing the malware's persistence across shell sessions.
On the other hand, the dock method involves downloading a signed dockutil tool from a command-and-control server to manage the dock items. The malware then creates a fake Launchpad application and replaces the legitimate Launchpad’s path entry in the dock with this fake one. This ensures that every time the Launchpad is started from the dock, both the legitimate Launchpad and the malicious payload are executed.
New infection techniques: The new XCSSET variant introduces new methods for where the payload is placed in a target Xcode project. The method is chosen from one of the following options: TARGET, RULE, or FORCED_STRATEGY. An additional method involves placing the payload inside the TARGET_DEVICE_FAMILY key under build settings and running it at a latter phase.
Microsoft Defender for Endpoint on Mac detects XCSSET, including this latest variant. Users must always inspect and verify any Xcode projects downloaded or cloned from repositories, as the malware usually spreads through infected projects. They should also only install apps from trusted sources, such as a software platform’s official app store.
Learn more about Defender for Endpoint on Mac: https://t.co/GXil88cF3a
Expectation as a Christian:
1. Glorious outcome in all you do
But if not, be it known unto thee, O king, that we will not serve thy gods, nor worship the golden image which thou hast set up.
-Daniel 3:18
For the LORD God is a sun and shield: The LORD will give grace and glory: No good thing will he withhold from them that walk uprightly. O LORD of hosts, Blessed is the man that trusteth in thee.
- Ps 84:11-12
Do not be anxious about anything, but in everything by prayer and supplication with thanksgiving let your requests be made known to God. - Philippians 4:6
Planning to relocate to Calgary? We provide airport pick-up services and are thrilled to assist with your smooth transition. Scan the QR code in the flyer to avail this service. God bless you!
All CV / Resume Complete Materials free😱🔥
Just Free Of Cost!!
Simply:
1. Follow(So that I can DM)
2. Like and Repost
3. Comment "CV" to receive your copies.
@_JohnHammond Hello John, I am new in the Cybersecurity space and really passionate and enthusiastic about growing my career in this field. I believe you can be part of my growth by learning from you as a connection. I will be definitely grateful if you accept my invite. Thanks