Skip to main content

A Deep Dive Into the Latest XCSSET Version

0
Medium
Published: 08/03/2026 (08/03/2026, 09:05:16 UTC)
Source: AlienVault OTX General

Description

After months of dormancy, XCSSET malware version 40 emerged in April 2026 targeting macOS developers through supply chain attacks. The malware hides in Xcode projects of legitimate applications on GitHub, spreading through infected development environments. V40 features advanced detection evasion through polymorphic payload generation, fileless persistence, and in-memory execution while weakening security mechanisms. It introduces 17 distinct modules including a Chrome hijacking backdoor via Chrome DevTools Protocol and a Telegram trojanizer. The malware employs multi-layered encryption, disables system security updates, terminates cloud telemetry, and locks XProtect signature databases. Primary targeting focuses on developers across South Asia. The infrastructure utilizes approximately 40 domains registered in Russia and India, demonstrating a geographic pivot in operations.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/03/2026, 13:53:40 UTC

Technical Analysis

XCSSET v40 is a sophisticated macOS malware targeting developers through infected Xcode projects hosted on GitHub, facilitating supply chain attacks. It employs polymorphic payload generation to evade detection, persists without files, and executes code in memory to weaken security mechanisms. The malware disables system security updates, terminates cloud telemetry, and locks XProtect signature databases to avoid detection and removal. It includes 17 distinct modules, notably a Chrome hijacking backdoor leveraging the Chrome DevTools Protocol and a Telegram trojanizer for further exploitation. The threat infrastructure involves approximately 40 domains registered in Russia and India, indicating a geographic pivot. The primary targets are developers in South Asia, aiming to compromise development environments and spread through legitimate software projects.

Potential Impact

The malware compromises macOS developer environments by infecting legitimate Xcode projects, enabling stealthy persistence and evasion of security controls. It disables critical system security updates and telemetry, increasing the risk of prolonged undetected presence. The inclusion of modules for browser hijacking and trojanizing Telegram clients expands the attack surface, potentially leading to credential theft, data exfiltration, and further lateral movement within targeted networks. The targeting of developers through supply chain attacks risks widespread downstream compromise of software built with infected projects.

Defensive Guidance

No official patch or remediation is indicated for this malware. Mitigation should focus on verifying the integrity of Xcode projects before use, especially those sourced from public repositories like GitHub. Developers should employ endpoint protection capable of detecting polymorphic and fileless malware behaviors and monitor for unusual disabling of system security features. Given the malware disables system updates and XProtect, manual verification and restoration of these services may be necessary. Users should avoid using development environments suspected of infection and consider rebuilding from clean sources. Regular backups and network segmentation may limit impact. Monitor the referenced vendor analysis for updates and detection signatures.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/"]
Pulse Id
6a7059ccae49a160e5763d1d

Indicators of Compromise

Ip

ValueDescriptionCopy
ip95.142.35.206
ip151.243.109.188
ip178.208.92.129
ip178.208.92.168
ip95.142.35.34
ip95.142.37.159
ip91.108.106.229

Domain

ValueDescriptionCopy
domainbulksec.ru
domainfigmacat.ru
domainwindsecure.ru
domainapplecdn.ru
domaincdnroute.ru
domaincheckcdn.ru
domainaccapple.ru
domainadschecks.ru
domainadsmobi.ru
domainadsmorein.in
domainadsmoreme.in
domainamdcdn.ru
domainamzndev.in
domainamzndev.ru
domainamznprod.in
domainappledisk.ru
domainappledns.ru
domainapplehosts.ru
domainappletime.in
domaincdnamz.in
domaincdnamz.ru
domaincdnapple.in
domaincdnatapple.ru
domainchromeads.ru
domaincnmag.ru
domaindevnetaps.ru
domaindnsapple.ru
domaindnsrelays.ru
domainexplorecdn.ru
domainfiddlejoy.ru
domainfigmanets.in
domainfunchats.ru
domaingironetcdn.ru
domaingoalmate.ru
domaingooglenets.ru
domaingreencn.ru
domainicloudsnet.ru
domainimails.ru
domainlegalads.in
domainlittleads.in
domainlittledns.ru
domainmaganet.ru
domainmindelgate.ru
domainnetapsdev.ru
domainnetcdnads.in
domainnetcdnamz.ru
domainnetcdndev.in
domainnetcorps.ru
domainnetsprot.in
domainnetsproto.in
domainnetworkads.in
domainrigacdn.in
domainrigmajoys.in
domainrigmanet.ru
domainrigmanets.in
domainsahusuzuki.in
domainstuffdns.in
domaintestjoys.ru
domaintimewebnet.in
domainvigmanet.ru
domainwhitead.in
domainwhiteads.ru
domainwincdn.ru

Hash

ValueDescriptionCopy
hash6e480d648fa1b70612f5d198a66875e28847547d

Threat ID: 6a70604dbf32cb7a345723eb

Added to database: 08/03/2026, 09:33:01 UTC

Last enriched: 08/03/2026, 13:53:40 UTC

Last updated: 09/17/2026, 16:53:31 UTC

Views: 147

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses