Malware
XCSSET
Indicators of Compromise 86
Domain accapple[.]ru Domain adschecks[.]ru Domain adsmobi[.]ru Domain adsmorein[.]in Domain adsmoreme[.]in Domain amdcdn[.]ru Domain amzndev[.]in Domain amzndev[.]ru Domain amznprod[.]in Domain applecdn[.]ru Domain appledisk[.]ru Domain appledns[.]ru Domain appletime[.]in Domain bulksec[.]ru Domain cdnamz[.]in Domain cdnamz[.]ru Domain cdnapple[.]in Domain cdnatapple[.]ru Domain cdnroute[.]ru Domain checkcdn[.]ru Domain chromeads[.]ru Domain cnmag[.]ru Domain devnetaps[.]ru Domain dnsapple[.]ru Domain dnsrelays[.]ru Domain explorecdn[.]ru Domain fiddlejoy[.]ru Domain figmacat[.]ru Domain figmanets[.]in Domain funchats[.]ru Domain gironetcdn[.]ru Domain goalmate[.]ru Domain googlenets[.]ru Domain greencn[.]ru Domain icloudsnet[.]ru Domain imails[.]ru Domain legalads[.]in Domain littleads[.]in Domain littledns[.]ru Domain maganet[.]ru Domain mindelgate[.]ru Domain netapsdev[.]ru Domain netcdnads[.]in Domain netcdndev[.]in Domain netcdndev[.]ru Domain netcorps[.]ru Domain netsprot[.]in Domain netsproto[.]in Domain networkads[.]in Domain rigacdn[.]in Domain rigmajoys[.]in Domain rigmanet[.]ru Domain rigmanets[.]in Domain sahusuzuki[.]in Domain stuffdns[.]in Domain testjoys[.]ru Domain timewebnet[.]in Domain vigmanet[.]ru Domain whitead[.]in Domain whiteads[.]ru Domain wincdn[.]ru Domain windsecure[.]ru Filename .cursorrules Filename .tr Filename .tr_map Filename AccountGuard.zip Filename CLAUDE.md Filename Telegram.app Filename base_tr_file.txt Filename base_tr_map.txt Filename chrome_remote Filename zw_sfp64 GitHub Repo Hunt.io GitHub Repo Xcode project on GitHub GitHub User Hunt.io SHA-1 6e480d648fa1b70612f5d198a66875e28847547d IP 151[.]243[.]109[.]188 IP 178[.]208[.]92[.]129 IP 178[.]208[.]92[.]168 IP 193[.]233[.]202[.]17 IP 91[.]108[.]106[.]229 IP 95[.]142[.]35[.]206 IP 95[.]142[.]35[.]34 IP 95[.]142[.]37[.]159 Registry User mpirv_eahpi_apm Registry User ychax_muwch_ucy
MITRE ATT&CK TTPs 43
T1001 T1003 T1012 T1016 T1021.001 T1027 T1040 T1053.005 T1055 T1056.003 T1057 T1059.001 T1059.004 T1070 T1070.004 T1070.006 T1071.001 T1071.004 T1074.001 T1080 T1082 T1083 T1087.002 T1090 T1090.004 T1095 T1098.004 T1105 T1112 T1113 T1129 T1133 T1204.002 T1210 T1485 T1496 T1497 T1548 T1553 T1555 T1557.001 T1566 T1647
Data Obfuscation
Command And Control
OS Credential Dumping
Credential Access
Query Registry
Discovery
System Network Configuration Discovery
Discovery
Remote Desktop Protocol
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Network Sniffing
Credential Access
Scheduled Task
Execution
Process Injection
Defense Evasion
Web Portal Capture
Collection
Process Discovery
Discovery
PowerShell
Execution
Unix Shell
Execution
Indicator Removal
Defense Evasion
File Deletion
Defense Evasion
Timestomp
Defense Evasion
Web Protocols
Command And Control
DNS
Command And Control
Local Data Staging
Collection
Taint Shared Content
Lateral Movement
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Domain Account
Discovery
Proxy
Command And Control
Domain Fronting
Command And Control
Non-Application Layer Protocol
Command And Control
SSH Authorized Keys
Persistence
Ingress Tool Transfer
Command And Control
Modify Registry
Defense Evasion
Screen Capture
Collection
Shared Modules
Execution
External Remote Services
Persistence
Malicious File
Execution
Exploitation of Remote Services
Lateral Movement
Data Destruction
Impact
Resource Hijacking
Impact
Virtualization/Sandbox Evasion
Defense Evasion
Abuse Elevation Control Mechanism
Privilege Escalation
Subvert Trust Controls
Defense Evasion
Credentials from Password Stores
Credential Access
LLMNR/NBT-NS Poisoning and SMB Relay
Credential Access
Phishing
Initial Access
Plist File Modification
Defense Evasion
Source Articles
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Multiple active threat campaigns were reported, including a new SideWinder attack chain using ClickOnce files to deploy Rust-based backdoors, a large-scale npm supply chain attack named 'Flooding Dropper' involving 846 malicious packages, and a Chinese threat actor leveraging a DeepSeek AI agent in an LLM-managed campaign for proxyjacking. A new XCSSET macOS malware variant (v40) spreads via compromised Xcode projects and includes a Telegram trojanizer. The Gentlemen ransomware affiliate deployed EtherRAT, which retrieves C2 data from an Ethereum smart contract. Additionally, Interlock ransomware abused Volatility3 to extract credentials from memory, and a critical RCE flaw in the Odysseus AI workspace allowed authenticated users to execute OS commands. Several phishing campaigns used fake Bank of America and Coldcard wallet lures to install ScreenConnect, while AI-powered scam farms like FunFoneFarm lower the barrier to entry for cybercrime.
hacker-news ·3w ago
New XCSSET variant targets macOS devs via compromised Xcode projects
A new variant of the XCSSET malware, version 40, is targeting macOS developers by compromising Xcode projects and GitHub repositories. The malware spreads when developers build infected projects, enabling it to propagate across systems and deploy 17 modules for credential theft, keystroke logging, clipboard manipulation, browser hijacking, and data exfiltration. This variant includes new capabilities such as a Chrome hijacker that enables real-time web traffic interception and a Telegram trojanizer that replaces the legitimate Telegram Desktop app with a malicious version. The malware employs advanced evasion techniques, disables macOS security features, and uses encrypted, build-unique ciphers to avoid detection.
bleeping-computer ·4w ago
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
XCSSET v40 is a sophisticated macOS malware that resurfaced in April 2026, targeting developers through supply chain attacks on Xcode projects hosted on GitHub. The malware uses a multi-stage infection chain involving memory-resident execution, polymorphic payloads, and fileless persistence to evade detection. It spreads by infecting Xcode projects and Git repositories, then downloads and executes additional modules from a command-and-control (C2) server, including a Chrome hijacking backdoor and a Telegram trojanizer. The malware disables macOS security mechanisms, blocks software updates, and manipulates browser sessions to steal credentials, cryptocurrency, and sensitive data.
unit42 ·4w ago