A Deep Dive Into the Latest XCSSET Version
After months of dormancy, XCSSET malware version 40 emerged in April 2026 targeting macOS developers through supply chain attacks. The malware hides in Xcode projects of legitimate applications on GitHub, spreading through infected development environments. V40 features advanced detection evasion through polymorphic payload generation, fileless persistence, and in-memory execution while weakening security mechanisms. It introduces 17 distinct modules including a Chrome hijacking backdoor via Chrome DevTools Protocol and a Telegram trojanizer. The malware employs multi-layered encryption, disables system security updates, terminates cloud telemetry, and locks XProtect signature databases. Primary targeting focuses on developers across South Asia. The infrastructure utilizes approximately 40 domains registered in Russia and India, demonstrating a geographic pivot in operations.
AI Analysis
Technical Summary
XCSSET v40 is a sophisticated macOS malware targeting developers through infected Xcode projects hosted on GitHub, facilitating supply chain attacks. It employs polymorphic payload generation to evade detection, persists without files, and executes code in memory to weaken security mechanisms. The malware disables system security updates, terminates cloud telemetry, and locks XProtect signature databases to avoid detection and removal. It includes 17 distinct modules, notably a Chrome hijacking backdoor leveraging the Chrome DevTools Protocol and a Telegram trojanizer for further exploitation. The threat infrastructure involves approximately 40 domains registered in Russia and India, indicating a geographic pivot. The primary targets are developers in South Asia, aiming to compromise development environments and spread through legitimate software projects.
Potential Impact
The malware compromises macOS developer environments by infecting legitimate Xcode projects, enabling stealthy persistence and evasion of security controls. It disables critical system security updates and telemetry, increasing the risk of prolonged undetected presence. The inclusion of modules for browser hijacking and trojanizing Telegram clients expands the attack surface, potentially leading to credential theft, data exfiltration, and further lateral movement within targeted networks. The targeting of developers through supply chain attacks risks widespread downstream compromise of software built with infected projects.
Mitigation Recommendations
No official patch or remediation is indicated for this malware. Mitigation should focus on verifying the integrity of Xcode projects before use, especially those sourced from public repositories like GitHub. Developers should employ endpoint protection capable of detecting polymorphic and fileless malware behaviors and monitor for unusual disabling of system security features. Given the malware disables system updates and XProtect, manual verification and restoration of these services may be necessary. Users should avoid using development environments suspected of infection and consider rebuilding from clean sources. Regular backups and network segmentation may limit impact. Monitor the referenced vendor analysis for updates and detection signatures.
Indicators of Compromise
- ip: 95.142.35.206
- domain: bulksec.ru
- domain: figmacat.ru
- domain: windsecure.ru
- domain: applecdn.ru
- domain: cdnroute.ru
- domain: checkcdn.ru
- hash: 6e480d648fa1b70612f5d198a66875e28847547d
- ip: 151.243.109.188
- ip: 178.208.92.129
- ip: 178.208.92.168
- ip: 95.142.35.34
- ip: 95.142.37.159
- domain: accapple.ru
- domain: adschecks.ru
- domain: adsmobi.ru
- domain: adsmorein.in
- domain: adsmoreme.in
- domain: amdcdn.ru
- domain: amzndev.in
- domain: amzndev.ru
- domain: amznprod.in
- domain: appledisk.ru
- domain: appledns.ru
- domain: applehosts.ru
- domain: appletime.in
- domain: cdnamz.in
- domain: cdnamz.ru
- domain: cdnapple.in
- domain: cdnatapple.ru
- domain: chromeads.ru
- domain: cnmag.ru
- domain: devnetaps.ru
- domain: dnsapple.ru
- domain: dnsrelays.ru
- domain: explorecdn.ru
- domain: fiddlejoy.ru
- domain: figmanets.in
- domain: funchats.ru
- domain: gironetcdn.ru
- domain: goalmate.ru
- domain: googlenets.ru
- domain: greencn.ru
- domain: icloudsnet.ru
- domain: imails.ru
- domain: legalads.in
- domain: littleads.in
- domain: littledns.ru
- domain: maganet.ru
- domain: mindelgate.ru
- domain: netapsdev.ru
- domain: netcdnads.in
- domain: netcdnamz.ru
- domain: netcdndev.in
- domain: netcorps.ru
- domain: netsprot.in
- domain: netsproto.in
- domain: networkads.in
- domain: rigacdn.in
- domain: rigmajoys.in
- domain: rigmanet.ru
- domain: rigmanets.in
- domain: sahusuzuki.in
- domain: stuffdns.in
- domain: testjoys.ru
- domain: timewebnet.in
- domain: vigmanet.ru
- domain: whitead.in
- domain: whiteads.ru
- domain: wincdn.ru
- ip: 91.108.106.229
A Deep Dive Into the Latest XCSSET Version
Description
After months of dormancy, XCSSET malware version 40 emerged in April 2026 targeting macOS developers through supply chain attacks. The malware hides in Xcode projects of legitimate applications on GitHub, spreading through infected development environments. V40 features advanced detection evasion through polymorphic payload generation, fileless persistence, and in-memory execution while weakening security mechanisms. It introduces 17 distinct modules including a Chrome hijacking backdoor via Chrome DevTools Protocol and a Telegram trojanizer. The malware employs multi-layered encryption, disables system security updates, terminates cloud telemetry, and locks XProtect signature databases. Primary targeting focuses on developers across South Asia. The infrastructure utilizes approximately 40 domains registered in Russia and India, demonstrating a geographic pivot in operations.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
XCSSET v40 is a sophisticated macOS malware targeting developers through infected Xcode projects hosted on GitHub, facilitating supply chain attacks. It employs polymorphic payload generation to evade detection, persists without files, and executes code in memory to weaken security mechanisms. The malware disables system security updates, terminates cloud telemetry, and locks XProtect signature databases to avoid detection and removal. It includes 17 distinct modules, notably a Chrome hijacking backdoor leveraging the Chrome DevTools Protocol and a Telegram trojanizer for further exploitation. The threat infrastructure involves approximately 40 domains registered in Russia and India, indicating a geographic pivot. The primary targets are developers in South Asia, aiming to compromise development environments and spread through legitimate software projects.
Potential Impact
The malware compromises macOS developer environments by infecting legitimate Xcode projects, enabling stealthy persistence and evasion of security controls. It disables critical system security updates and telemetry, increasing the risk of prolonged undetected presence. The inclusion of modules for browser hijacking and trojanizing Telegram clients expands the attack surface, potentially leading to credential theft, data exfiltration, and further lateral movement within targeted networks. The targeting of developers through supply chain attacks risks widespread downstream compromise of software built with infected projects.
Defensive Guidance
No official patch or remediation is indicated for this malware. Mitigation should focus on verifying the integrity of Xcode projects before use, especially those sourced from public repositories like GitHub. Developers should employ endpoint protection capable of detecting polymorphic and fileless malware behaviors and monitor for unusual disabling of system security features. Given the malware disables system updates and XProtect, manual verification and restoration of these services may be necessary. Users should avoid using development environments suspected of infection and consider rebuilding from clean sources. Regular backups and network segmentation may limit impact. Monitor the referenced vendor analysis for updates and detection signatures.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/"]
- Pulse Id
- 6a7059ccae49a160e5763d1d
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip95.142.35.206 | — | |
ip151.243.109.188 | — | |
ip178.208.92.129 | — | |
ip178.208.92.168 | — | |
ip95.142.35.34 | — | |
ip95.142.37.159 | — | |
ip91.108.106.229 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainbulksec.ru | — | |
domainfigmacat.ru | — | |
domainwindsecure.ru | — | |
domainapplecdn.ru | — | |
domaincdnroute.ru | — | |
domaincheckcdn.ru | — | |
domainaccapple.ru | — | |
domainadschecks.ru | — | |
domainadsmobi.ru | — | |
domainadsmorein.in | — | |
domainadsmoreme.in | — | |
domainamdcdn.ru | — | |
domainamzndev.in | — | |
domainamzndev.ru | — | |
domainamznprod.in | — | |
domainappledisk.ru | — | |
domainappledns.ru | — | |
domainapplehosts.ru | — | |
domainappletime.in | — | |
domaincdnamz.in | — | |
domaincdnamz.ru | — | |
domaincdnapple.in | — | |
domaincdnatapple.ru | — | |
domainchromeads.ru | — | |
domaincnmag.ru | — | |
domaindevnetaps.ru | — | |
domaindnsapple.ru | — | |
domaindnsrelays.ru | — | |
domainexplorecdn.ru | — | |
domainfiddlejoy.ru | — | |
domainfigmanets.in | — | |
domainfunchats.ru | — | |
domaingironetcdn.ru | — | |
domaingoalmate.ru | — | |
domaingooglenets.ru | — | |
domaingreencn.ru | — | |
domainicloudsnet.ru | — | |
domainimails.ru | — | |
domainlegalads.in | — | |
domainlittleads.in | — | |
domainlittledns.ru | — | |
domainmaganet.ru | — | |
domainmindelgate.ru | — | |
domainnetapsdev.ru | — | |
domainnetcdnads.in | — | |
domainnetcdnamz.ru | — | |
domainnetcdndev.in | — | |
domainnetcorps.ru | — | |
domainnetsprot.in | — | |
domainnetsproto.in | — | |
domainnetworkads.in | — | |
domainrigacdn.in | — | |
domainrigmajoys.in | — | |
domainrigmanet.ru | — | |
domainrigmanets.in | — | |
domainsahusuzuki.in | — | |
domainstuffdns.in | — | |
domaintestjoys.ru | — | |
domaintimewebnet.in | — | |
domainvigmanet.ru | — | |
domainwhitead.in | — | |
domainwhiteads.ru | — | |
domainwincdn.ru | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash6e480d648fa1b70612f5d198a66875e28847547d | — |
Threat ID: 6a70604dbf32cb7a345723eb
Added to database: 08/03/2026, 09:33:01 UTC
Last enriched: 08/03/2026, 13:53:40 UTC
Last updated: 09/17/2026, 16:53:31 UTC
Views: 147
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.