A Deep Dive Into the Latest XCSSET Version
XCSSET malware version 40, resurfacing in April 2026, targets macOS developers via supply chain attacks by infecting Xcode projects on GitHub. It uses advanced evasion techniques including polymorphic payloads, fileless persistence, and in-memory execution. The malware disables system security updates, cloud telemetry, and locks XProtect signature databases. It includes 17 modules such as a Chrome hijacking backdoor and a Telegram trojanizer. The campaign primarily targets developers in South Asia and operates through infrastructure with domains registered in Russia and India.
AI Analysis
Technical Summary
XCSSET v40 is a sophisticated macOS malware targeting developers through infected Xcode projects hosted on GitHub, facilitating supply chain attacks. It employs polymorphic payload generation to evade detection, persists without files, and executes code in memory to weaken security mechanisms. The malware disables system security updates, terminates cloud telemetry, and locks XProtect signature databases to avoid detection and removal. It includes 17 distinct modules, notably a Chrome hijacking backdoor leveraging the Chrome DevTools Protocol and a Telegram trojanizer for further exploitation. The threat infrastructure involves approximately 40 domains registered in Russia and India, indicating a geographic pivot. The primary targets are developers in South Asia, aiming to compromise development environments and spread through legitimate software projects.
Potential Impact
The malware compromises macOS developer environments by infecting legitimate Xcode projects, enabling stealthy persistence and evasion of security controls. It disables critical system security updates and telemetry, increasing the risk of prolonged undetected presence. The inclusion of modules for browser hijacking and trojanizing Telegram clients expands the attack surface, potentially leading to credential theft, data exfiltration, and further lateral movement within targeted networks. The targeting of developers through supply chain attacks risks widespread downstream compromise of software built with infected projects.
Mitigation Recommendations
No official patch or remediation is indicated for this malware. Mitigation should focus on verifying the integrity of Xcode projects before use, especially those sourced from public repositories like GitHub. Developers should employ endpoint protection capable of detecting polymorphic and fileless malware behaviors and monitor for unusual disabling of system security features. Given the malware disables system updates and XProtect, manual verification and restoration of these services may be necessary. Users should avoid using development environments suspected of infection and consider rebuilding from clean sources. Regular backups and network segmentation may limit impact. Monitor the referenced vendor analysis for updates and detection signatures.
Indicators of Compromise
- ip: 95.142.35.206
- domain: bulksec.ru
- domain: figmacat.ru
- domain: windsecure.ru
- domain: applecdn.ru
- domain: cdnroute.ru
- domain: checkcdn.ru
- hash: 6e480d648fa1b70612f5d198a66875e28847547d
- ip: 151.243.109.188
- ip: 178.208.92.129
- ip: 178.208.92.168
- ip: 95.142.35.34
- ip: 95.142.37.159
- domain: accapple.ru
- domain: adschecks.ru
- domain: adsmobi.ru
- domain: adsmorein.in
- domain: adsmoreme.in
- domain: amdcdn.ru
- domain: amzndev.in
- domain: amzndev.ru
- domain: amznprod.in
- domain: appledisk.ru
- domain: appledns.ru
- domain: applehosts.ru
- domain: appletime.in
- domain: cdnamz.in
- domain: cdnamz.ru
- domain: cdnapple.in
- domain: cdnatapple.ru
- domain: chromeads.ru
- domain: cnmag.ru
- domain: devnetaps.ru
- domain: dnsapple.ru
- domain: dnsrelays.ru
- domain: explorecdn.ru
- domain: fiddlejoy.ru
- domain: figmanets.in
- domain: funchats.ru
- domain: gironetcdn.ru
- domain: goalmate.ru
- domain: googlenets.ru
- domain: greencn.ru
- domain: icloudsnet.ru
- domain: imails.ru
- domain: legalads.in
- domain: littleads.in
- domain: littledns.ru
- domain: maganet.ru
- domain: mindelgate.ru
- domain: netapsdev.ru
- domain: netcdnads.in
- domain: netcdnamz.ru
- domain: netcdndev.in
- domain: netcorps.ru
- domain: netsprot.in
- domain: netsproto.in
- domain: networkads.in
- domain: rigacdn.in
- domain: rigmajoys.in
- domain: rigmanet.ru
- domain: rigmanets.in
- domain: sahusuzuki.in
- domain: stuffdns.in
- domain: testjoys.ru
- domain: timewebnet.in
- domain: vigmanet.ru
- domain: whitead.in
- domain: whiteads.ru
- domain: wincdn.ru
- ip: 91.108.106.229
A Deep Dive Into the Latest XCSSET Version
Description
XCSSET malware version 40, resurfacing in April 2026, targets macOS developers via supply chain attacks by infecting Xcode projects on GitHub. It uses advanced evasion techniques including polymorphic payloads, fileless persistence, and in-memory execution. The malware disables system security updates, cloud telemetry, and locks XProtect signature databases. It includes 17 modules such as a Chrome hijacking backdoor and a Telegram trojanizer. The campaign primarily targets developers in South Asia and operates through infrastructure with domains registered in Russia and India.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
XCSSET v40 is a sophisticated macOS malware targeting developers through infected Xcode projects hosted on GitHub, facilitating supply chain attacks. It employs polymorphic payload generation to evade detection, persists without files, and executes code in memory to weaken security mechanisms. The malware disables system security updates, terminates cloud telemetry, and locks XProtect signature databases to avoid detection and removal. It includes 17 distinct modules, notably a Chrome hijacking backdoor leveraging the Chrome DevTools Protocol and a Telegram trojanizer for further exploitation. The threat infrastructure involves approximately 40 domains registered in Russia and India, indicating a geographic pivot. The primary targets are developers in South Asia, aiming to compromise development environments and spread through legitimate software projects.
Potential Impact
The malware compromises macOS developer environments by infecting legitimate Xcode projects, enabling stealthy persistence and evasion of security controls. It disables critical system security updates and telemetry, increasing the risk of prolonged undetected presence. The inclusion of modules for browser hijacking and trojanizing Telegram clients expands the attack surface, potentially leading to credential theft, data exfiltration, and further lateral movement within targeted networks. The targeting of developers through supply chain attacks risks widespread downstream compromise of software built with infected projects.
Mitigation Recommendations
No official patch or remediation is indicated for this malware. Mitigation should focus on verifying the integrity of Xcode projects before use, especially those sourced from public repositories like GitHub. Developers should employ endpoint protection capable of detecting polymorphic and fileless malware behaviors and monitor for unusual disabling of system security features. Given the malware disables system updates and XProtect, manual verification and restoration of these services may be necessary. Users should avoid using development environments suspected of infection and consider rebuilding from clean sources. Regular backups and network segmentation may limit impact. Monitor the referenced vendor analysis for updates and detection signatures.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/"]
- Adversary
- null
- Pulse Id
- 6a7059ccae49a160e5763d1d
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip95.142.35.206 | — | |
ip151.243.109.188 | — | |
ip178.208.92.129 | — | |
ip178.208.92.168 | — | |
ip95.142.35.34 | — | |
ip95.142.37.159 | — | |
ip91.108.106.229 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainbulksec.ru | — | |
domainfigmacat.ru | — | |
domainwindsecure.ru | — | |
domainapplecdn.ru | — | |
domaincdnroute.ru | — | |
domaincheckcdn.ru | — | |
domainaccapple.ru | — | |
domainadschecks.ru | — | |
domainadsmobi.ru | — | |
domainadsmorein.in | — | |
domainadsmoreme.in | — | |
domainamdcdn.ru | — | |
domainamzndev.in | — | |
domainamzndev.ru | — | |
domainamznprod.in | — | |
domainappledisk.ru | — | |
domainappledns.ru | — | |
domainapplehosts.ru | — | |
domainappletime.in | — | |
domaincdnamz.in | — | |
domaincdnamz.ru | — | |
domaincdnapple.in | — | |
domaincdnatapple.ru | — | |
domainchromeads.ru | — | |
domaincnmag.ru | — | |
domaindevnetaps.ru | — | |
domaindnsapple.ru | — | |
domaindnsrelays.ru | — | |
domainexplorecdn.ru | — | |
domainfiddlejoy.ru | — | |
domainfigmanets.in | — | |
domainfunchats.ru | — | |
domaingironetcdn.ru | — | |
domaingoalmate.ru | — | |
domaingooglenets.ru | — | |
domaingreencn.ru | — | |
domainicloudsnet.ru | — | |
domainimails.ru | — | |
domainlegalads.in | — | |
domainlittleads.in | — | |
domainlittledns.ru | — | |
domainmaganet.ru | — | |
domainmindelgate.ru | — | |
domainnetapsdev.ru | — | |
domainnetcdnads.in | — | |
domainnetcdnamz.ru | — | |
domainnetcdndev.in | — | |
domainnetcorps.ru | — | |
domainnetsprot.in | — | |
domainnetsproto.in | — | |
domainnetworkads.in | — | |
domainrigacdn.in | — | |
domainrigmajoys.in | — | |
domainrigmanet.ru | — | |
domainrigmanets.in | — | |
domainsahusuzuki.in | — | |
domainstuffdns.in | — | |
domaintestjoys.ru | — | |
domaintimewebnet.in | — | |
domainvigmanet.ru | — | |
domainwhitead.in | — | |
domainwhiteads.ru | — | |
domainwincdn.ru | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash6e480d648fa1b70612f5d198a66875e28847547d | — |
Threat ID: 6a70604dbf32cb7a345723eb
Added to database: 08/03/2026, 09:33:01 UTC
Last enriched: 08/03/2026, 13:53:40 UTC
Last updated: 08/03/2026, 14:57:13 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.