Malware

XCSSET

Indicators of Compromise 86

Domain accapple[.]ru Domain adschecks[.]ru Domain adsmobi[.]ru Domain adsmorein[.]in Domain adsmoreme[.]in Domain amdcdn[.]ru Domain amzndev[.]in Domain amzndev[.]ru Domain amznprod[.]in Domain applecdn[.]ru Domain appledisk[.]ru Domain appledns[.]ru Domain appletime[.]in Domain bulksec[.]ru Domain cdnamz[.]in Domain cdnamz[.]ru Domain cdnapple[.]in Domain cdnatapple[.]ru Domain cdnroute[.]ru Domain checkcdn[.]ru Domain chromeads[.]ru Domain cnmag[.]ru Domain devnetaps[.]ru Domain dnsapple[.]ru Domain dnsrelays[.]ru Domain explorecdn[.]ru Domain fiddlejoy[.]ru Domain figmacat[.]ru Domain figmanets[.]in Domain funchats[.]ru Domain gironetcdn[.]ru Domain goalmate[.]ru Domain googlenets[.]ru Domain greencn[.]ru Domain icloudsnet[.]ru Domain imails[.]ru Domain legalads[.]in Domain littleads[.]in Domain littledns[.]ru Domain maganet[.]ru Domain mindelgate[.]ru Domain netapsdev[.]ru Domain netcdnads[.]in Domain netcdndev[.]in Domain netcdndev[.]ru Domain netcorps[.]ru Domain netsprot[.]in Domain netsproto[.]in Domain networkads[.]in Domain rigacdn[.]in Domain rigmajoys[.]in Domain rigmanet[.]ru Domain rigmanets[.]in Domain sahusuzuki[.]in Domain stuffdns[.]in Domain testjoys[.]ru Domain timewebnet[.]in Domain vigmanet[.]ru Domain whitead[.]in Domain whiteads[.]ru Domain wincdn[.]ru Domain windsecure[.]ru Filename .cursorrules Filename .tr Filename .tr_map Filename AccountGuard.zip Filename CLAUDE.md Filename Telegram.app Filename base_tr_file.txt Filename base_tr_map.txt Filename chrome_remote Filename zw_sfp64 GitHub Repo Hunt.io GitHub Repo Xcode project on GitHub GitHub User Hunt.io SHA-1 6e480d648fa1b70612f5d198a66875e28847547d IP 151[.]243[.]109[.]188 IP 178[.]208[.]92[.]129 IP 178[.]208[.]92[.]168 IP 193[.]233[.]202[.]17 IP 91[.]108[.]106[.]229 IP 95[.]142[.]35[.]206 IP 95[.]142[.]35[.]34 IP 95[.]142[.]37[.]159 Registry User mpirv_eahpi_apm Registry User ychax_muwch_ucy

MITRE ATT&CK TTPs 43

T1001
Data Obfuscation
Command And Control
T1003
OS Credential Dumping
Credential Access
T1012
Query Registry
Discovery
T1016
System Network Configuration Discovery
Discovery
T1021.001
Remote Desktop Protocol
Lateral Movement
T1027
Obfuscated Files or Information
Defense Evasion
T1040
Network Sniffing
Credential Access
T1053.005
Scheduled Task
Execution
T1055
Process Injection
Defense Evasion
T1056.003
Web Portal Capture
Collection
T1057
Process Discovery
Discovery
T1059.001
PowerShell
Execution
T1059.004
Unix Shell
Execution
T1070
Indicator Removal
Defense Evasion
T1070.004
File Deletion
Defense Evasion
T1070.006
Timestomp
Defense Evasion
T1071.001
Web Protocols
Command And Control
T1071.004
DNS
Command And Control
T1074.001
Local Data Staging
Collection
T1080
Taint Shared Content
Lateral Movement
T1082
System Information Discovery
Discovery
T1083
File and Directory Discovery
Discovery
T1087.002
Domain Account
Discovery
T1090
Proxy
Command And Control
T1090.004
Domain Fronting
Command And Control
T1095
Non-Application Layer Protocol
Command And Control
T1098.004
SSH Authorized Keys
Persistence
T1105
Ingress Tool Transfer
Command And Control
T1112
Modify Registry
Defense Evasion
T1113
Screen Capture
Collection
T1129
Shared Modules
Execution
T1133
External Remote Services
Persistence
T1204.002
Malicious File
Execution
T1210
Exploitation of Remote Services
Lateral Movement
T1485
Data Destruction
Impact
T1496
Resource Hijacking
Impact
T1497
Virtualization/Sandbox Evasion
Defense Evasion
T1548
Abuse Elevation Control Mechanism
Privilege Escalation
T1553
Subvert Trust Controls
Defense Evasion
T1555
Credentials from Password Stores
Credential Access
T1557.001
LLMNR/NBT-NS Poisoning and SMB Relay
Credential Access
T1566
Phishing
Initial Access
T1647
Plist File Modification
Defense Evasion

Source Articles

ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Multiple active threat campaigns were reported, including a new SideWinder attack chain using ClickOnce files to deploy Rust-based backdoors, a large-scale npm supply chain attack named 'Flooding Dropper' involving 846 malicious packages, and a Chinese threat actor leveraging a DeepSeek AI agent in an LLM-managed campaign for proxyjacking. A new XCSSET macOS malware variant (v40) spreads via compromised Xcode projects and includes a Telegram trojanizer. The Gentlemen ransomware affiliate deployed EtherRAT, which retrieves C2 data from an Ethereum smart contract. Additionally, Interlock ransomware abused Volatility3 to extract credentials from memory, and a critical RCE flaw in the Odysseus AI workspace allowed authenticated users to execute OS commands. Several phishing campaigns used fake Bank of America and Coldcard wallet lures to install ScreenConnect, while AI-powered scam farms like FunFoneFarm lower the barrier to entry for cybercrime.
hacker-news ·3w ago
New XCSSET variant targets macOS devs via compromised Xcode projects
A new variant of the XCSSET malware, version 40, is targeting macOS developers by compromising Xcode projects and GitHub repositories. The malware spreads when developers build infected projects, enabling it to propagate across systems and deploy 17 modules for credential theft, keystroke logging, clipboard manipulation, browser hijacking, and data exfiltration. This variant includes new capabilities such as a Chrome hijacker that enables real-time web traffic interception and a Telegram trojanizer that replaces the legitimate Telegram Desktop app with a malicious version. The malware employs advanced evasion techniques, disables macOS security features, and uses encrypted, build-unique ciphers to avoid detection.
bleeping-computer ·4w ago
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
XCSSET v40 is a sophisticated macOS malware that resurfaced in April 2026, targeting developers through supply chain attacks on Xcode projects hosted on GitHub. The malware uses a multi-stage infection chain involving memory-resident execution, polymorphic payloads, and fileless persistence to evade detection. It spreads by infecting Xcode projects and Git repositories, then downloads and executes additional modules from a command-and-control (C2) server, including a Chrome hijacking backdoor and a Telegram trojanizer. The malware disables macOS security mechanisms, blocks software updates, and manipulates browser sessions to steal credentials, cryptocurrency, and sensitive data.
unit42 ·4w ago