Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

A Deep Dive Into the Latest XCSSET Version

0
Medium
Published: 08/03/2026 (08/03/2026, 09:05:16 UTC)
Source: AlienVault OTX General

Description

XCSSET malware version 40, resurfacing in April 2026, targets macOS developers via supply chain attacks by infecting Xcode projects on GitHub. It uses advanced evasion techniques including polymorphic payloads, fileless persistence, and in-memory execution. The malware disables system security updates, cloud telemetry, and locks XProtect signature databases. It includes 17 modules such as a Chrome hijacking backdoor and a Telegram trojanizer. The campaign primarily targets developers in South Asia and operates through infrastructure with domains registered in Russia and India.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/03/2026, 13:53:40 UTC

Technical Analysis

XCSSET v40 is a sophisticated macOS malware targeting developers through infected Xcode projects hosted on GitHub, facilitating supply chain attacks. It employs polymorphic payload generation to evade detection, persists without files, and executes code in memory to weaken security mechanisms. The malware disables system security updates, terminates cloud telemetry, and locks XProtect signature databases to avoid detection and removal. It includes 17 distinct modules, notably a Chrome hijacking backdoor leveraging the Chrome DevTools Protocol and a Telegram trojanizer for further exploitation. The threat infrastructure involves approximately 40 domains registered in Russia and India, indicating a geographic pivot. The primary targets are developers in South Asia, aiming to compromise development environments and spread through legitimate software projects.

Potential Impact

The malware compromises macOS developer environments by infecting legitimate Xcode projects, enabling stealthy persistence and evasion of security controls. It disables critical system security updates and telemetry, increasing the risk of prolonged undetected presence. The inclusion of modules for browser hijacking and trojanizing Telegram clients expands the attack surface, potentially leading to credential theft, data exfiltration, and further lateral movement within targeted networks. The targeting of developers through supply chain attacks risks widespread downstream compromise of software built with infected projects.

Mitigation Recommendations

No official patch or remediation is indicated for this malware. Mitigation should focus on verifying the integrity of Xcode projects before use, especially those sourced from public repositories like GitHub. Developers should employ endpoint protection capable of detecting polymorphic and fileless malware behaviors and monitor for unusual disabling of system security features. Given the malware disables system updates and XProtect, manual verification and restoration of these services may be necessary. Users should avoid using development environments suspected of infection and consider rebuilding from clean sources. Regular backups and network segmentation may limit impact. Monitor the referenced vendor analysis for updates and detection signatures.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/"]
Adversary
null
Pulse Id
6a7059ccae49a160e5763d1d
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip95.142.35.206
ip151.243.109.188
ip178.208.92.129
ip178.208.92.168
ip95.142.35.34
ip95.142.37.159
ip91.108.106.229

Domain

ValueDescriptionCopy
domainbulksec.ru
domainfigmacat.ru
domainwindsecure.ru
domainapplecdn.ru
domaincdnroute.ru
domaincheckcdn.ru
domainaccapple.ru
domainadschecks.ru
domainadsmobi.ru
domainadsmorein.in
domainadsmoreme.in
domainamdcdn.ru
domainamzndev.in
domainamzndev.ru
domainamznprod.in
domainappledisk.ru
domainappledns.ru
domainapplehosts.ru
domainappletime.in
domaincdnamz.in
domaincdnamz.ru
domaincdnapple.in
domaincdnatapple.ru
domainchromeads.ru
domaincnmag.ru
domaindevnetaps.ru
domaindnsapple.ru
domaindnsrelays.ru
domainexplorecdn.ru
domainfiddlejoy.ru
domainfigmanets.in
domainfunchats.ru
domaingironetcdn.ru
domaingoalmate.ru
domaingooglenets.ru
domaingreencn.ru
domainicloudsnet.ru
domainimails.ru
domainlegalads.in
domainlittleads.in
domainlittledns.ru
domainmaganet.ru
domainmindelgate.ru
domainnetapsdev.ru
domainnetcdnads.in
domainnetcdnamz.ru
domainnetcdndev.in
domainnetcorps.ru
domainnetsprot.in
domainnetsproto.in
domainnetworkads.in
domainrigacdn.in
domainrigmajoys.in
domainrigmanet.ru
domainrigmanets.in
domainsahusuzuki.in
domainstuffdns.in
domaintestjoys.ru
domaintimewebnet.in
domainvigmanet.ru
domainwhitead.in
domainwhiteads.ru
domainwincdn.ru

Hash

ValueDescriptionCopy
hash6e480d648fa1b70612f5d198a66875e28847547d

Threat ID: 6a70604dbf32cb7a345723eb

Added to database: 08/03/2026, 09:33:01 UTC

Last enriched: 08/03/2026, 13:53:40 UTC

Last updated: 08/03/2026, 14:57:13 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses