Threat reportMalwareTL-2026-1870

XCSSET v40 macOS Malware Targeting Developers via Compromised Xcode Projects

highACTIVE

XCSSET v40 macOS Malware Targeting Developers via (TL-2026-1870), also tracked as XCSSET, is a high-severity malware campaign, first published 2026-08-04. It has no confirmed attribution, affects Apple macOS, maps to 22 MITRE ATT&CK techniques (T1027, T1036, T1055), and is covered by 9 detection rules and 28 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
22MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-1870

Threat ID
TL-2026-1870
Also known as
XCSSET, XCSSET v40, TrojanSpy.MacOS.XCSSET.A, Backdoor.MacOS.XCSSET.A
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, software-development, finance-crypto
Target regions
South Asia
Detection rules
9
Indicators of compromise
28

Malware and tooling in XCSSET v40 macOS Malware Targeting Developers via

Malware and tooling: XCSSET, Custom dual-key AES-256-CBC C2 protocol

How XCSSET v40 macOS Malware Targeting Developers via works

XCSSET v40, a new variant of the modular macOS malware family first discovered in 2020, has resurfaced with two attack waves (April and May 2026) targeting developers across South Asia through compromised Xcode projects on GitHub. The malware deploys 17 modules including two new components — a Chrome DevTools Protocol (CDP) backdoor enabling full browser session control and a fileless reverse shell, and a Telegram Desktop trojanizer — with polymorphic payload generation, dual-key AES-256-CBC encryption, and aggressive macOS security feature suppression (XProtect, MRT, TCC, Rapid Security Response).

XCSSET is a long-running macOS malware family first documented by Trend Micro in August 2020, notable for infecting Xcode projects to create supply-chain risks for macOS developers. The malware injects malicious build-phase scripts into .xcodeproj files so that compiling the project triggers execution. Version 40 (v40), analyzed by Palo Alto Networks Unit 42 after a dormant period, represents a significant escalation in capability and stealth.

The infection chain operates in four stages. Stage 1: an attacker compromises Git repositories and injects a downloader script into the Xcode project build phases of legitimate .xcodeproj files; when a developer builds the project locally, a run-script phase executes silently, contacting the C2 via curl to /a with parameter p=xcode_phase. Stage 2: the staging payload performs reconnaissance — querying uname -s (OS type) and whoami (username) — exfiltrating host metadata to the C2. Stage 3: the C2 returns a Bash script obfuscated via a custom substitution cipher, performing hardware fingerprinting against targeted serial profiles, then pulling the primary loader to /tmp/r and compiling an AppleScript wrapper as /tmp/p.app; the loader executes in-memory via osascript. Stage 4: the main orchestrator (named 'boot') runs entirely in memory, retrieving additional modules from the C2 via HTTPS, piping payloads to AppleScript for in-memory decryption and execution, then terminating all staging processes and deleting installation files from disk.

XCSSET v40 delivers 17 modular components, each with a distinct function. The orchestrator 'boot' dispatches modules including stats (reconnaissance, anti-VM, browser extension exfiltration), clipboard_v2 (keyboard hijacker), payloader (secondary dispatcher), replicator_finder (Xcode project file infector), git_finder (Git pre-commit hook infector), zip_infect_finder (NEW — traverses directories to find/infect Xcode projects inside .zip archives), data_folders_finder (C2-driven folder finder and exfiltrator), firefox_data (Firefox infostealer), notes_app (Apple Notes exfiltrator), settings_app (LaunchDaemon persistence via fake Settings.app; blocks XProtect), finder_app (TCC permission abuse; creates trojanized apps mimicking Finder/Xcode/Terminal/Reminders/SimulatorTrampoline), persist (.zshrc and Dock-based persistence), browser_remote (unified browser hijack dispatcher), safari_remote (Safari hijacker), chrome_remote (NEW — Chrome CDP backdoor), and tdesktop (NEW — Telegram Desktop trojanizer).

The two new modules in v40 are the most significant additions. The Chrome hijacker (chrome_remote) wraps the legitimate Google Chrome binary in a malicious launcher: when Chrome launches, the malware restarts the boot orchestrator, activates Chrome DevTools Protocol (CDP) on localhost:18907, and drops a helper binary that connects to CDP. This helper establishes a persistent WebSocket connection to the C2, injects JavaScript before pages load, hooks window.fetch and XMLHttpRequest to exfiltrate credentials and API tokens, intercepts MetaMask's Ethereum provider to manipulate cryptocurrency transactions, and overrides password-manager autofill fields. It also monitors browser console events; when the operator sends a console.log with a specific delimiter prefix, chrome_remote executes the payload via exec.Command on the host, creating a fileless reverse shell routed through the CDP WebSocket. Google has protections against CDP abuse on Windows and is extending defenses to macOS.

The Telegram Desktop trojanizer (tdesktop), which appeared in the May 2026 wave but not the April deployment, downloads a pre-built malicious Telegram.app ZIP from the C2, deletes the legitimate copy, drops the replacement, ad hoc code-signs it, and kills the original Telegram process so the victim relaunches the trojanized copy. Its configuration is AES-encrypted and stored in ~/.tr.

XCSSET v40 employs aggressive evasion. The loader binary is recompiled on the C2 every few hours — Unit 42 observed 8 distinct hashes delivered to one endpoint in 24 hours. A dual-key encryption architecture uses separate AES-256-CBC keys for inbound versus outbound C2 traffic; the inbound key embedded in the compiled AppleScript loader means network telemetry alone cannot decrypt core logic. String literals use per-module keyed Caesar ciphers with randomized 52-character alphabets and variable shift values, ensuring no two builds share common string signatures. Function, module, and variable names are scrambled server-side via a substitution cipher before distribution, with the decryption mapping absent from the endpoint.

The malware aggressively disables macOS security: it blocks XProtect signature updates, disables MRT (Malware Removal Tool) updates, resets the TCC database, blocks Rapid Security Response delivery, and runs a constant loop terminating Apple's CloudTelemetryService. It spawns a Perl process to acquire and hold an exclusive file lock on the YARA-rule database (XPdb), preventing security update writes. When the user denies AppleEvents automation, it invokes tccutil reset AppleEvents and re-prompts with a dialog masquerading as System Settings or Xcode. The stats module performs anti-VM checks via CPU and hardware metadata and withholds module delivery from identified virtual machines.

C2 infrastructure includes approximately 64 domains registered in four short bursts during early 2026 from a small IP pool, aged for months before activation to bypass new-domain detection. Domains shifted from .ru TLDs in 2025 campaigns to .in TLDs in 2026, consistent with South Asian targeting. Operator OPSEC failures include cross-contaminated IP addresses across different XCSSET campaigns, a shared SSL certificate thumbprint (6e480d648fa1b70612f5d198a66875e28847547d) across all four operator IPs, and reused SSH keys and a self-signed RDP certificate.

Attribution remains unclear; no named APT group or nation-state has been assigned. Geographic targeting concentrates on South Asia, consistent with Trend Micro's 2020 reporting. The primary motivation appears financial given the cryptocurrency address manipulation, credential theft, and session hijacking, though the malware's data exfiltration capabilities could serve espionage objectives. The supply-chain vector targeting macOS developers through GitHub compromises gives the malware exceptional reach, with infected Xcode projects belonging to dozens of legitimate applications with thousands of active users.

MITRE ATT&CK techniques used in TL-2026-1870

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion

Privilege Escalation

T1055 Process Injection

Credential Access

T1056 Input Capture; T1555 Credentials from Password Stores

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1573 Encrypted Channel

Discovery

T1082 System Information Discovery; T1518 Software Discovery

collection

T1185 Browser Session Hijacking

Initial Access

T1195 Supply Chain Compromise

Impact

T1489 Service Stop

Persistence

T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution; T1554 Compromise Host Software Binary

Collection

T1560 Archive Collected Data

stealth

T1574 Hijack Execution Flow

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in XCSSET v40 macOS Malware Targeting Developers via

  • Apple — macOS
    Vulnerable versions: macOS Sonoma; macOS Sequoia; All versions with Xcode installed
  • Apple — Xcode
    Vulnerable versions: All versions
  • Google — Chrome for macOS
    Vulnerable versions: Versions prior to CDP abuse mitigation
  • Telegram — Telegram Desktop for macOS
    Vulnerable versions: All versions (binary replacement, not vulnerability)
  • Apple — XProtect
    Vulnerable versions: Versions vulnerable to file lock denial-of-service

Remediation for XCSSET v40 macOS Malware Targeting Developers via

Patches

  • Update macOS to latest version for XProtect and TCC improvements
  • Update Google Chrome to latest version for CDP abuse mitigations
  • Ensure Gatekeeper is enabled and ad hoc-signed applications require user approval

Immediate actions

  • Inspect Xcode projects for unfamiliar build phases or run-script entries referencing curl downloads
  • Scan Git repositories for suspicious pre-commit hooks and modified .xcodeproj/.pbxproj files
  • Monitor for Chrome launched with --remote-debugging-port= arguments
  • Block C2 domains (amzndev.in, googlenets.ru, whiteads.ru and ~60 others) at network perimeter
  • Isolate and investigate any macOS hosts with unusual defaults preferences activity
  • Check for ad hoc-signed applications replacing legitimate binaries (especially Telegram.app)

Workarounds

  • Disable automatic Xcode project build for projects cloned from untrusted sources
  • Review and validate all Xcode project build phases before building third-party projects
  • Use containerized or isolated build environments for compiling open-source Xcode projects
  • Restrict automation permissions for applications under System Settings > Privacy & Security > Automation

Longer-term hardening

  • Deploy EDR rules monitoring AppleScript (osascript) execution initiated by Xcode build processes
  • Implement behavioral detection for Chrome launched with CDP flags or unexpected browser process ancestry
  • Deploy detection for macOS defaults domain writes with encoded/obfuscated payload values
  • Monitor for Perl processes holding exclusive file locks on XProtect database paths
  • Implement detection for repeated tccutil reset commands and automation permission prompts
  • Deploy file integrity monitoring for Xcode project files and Git hook directories

Timeline of XCSSET v40 macOS Malware Targeting Developers via

  • Trend Micro discovers XCSSET targeting macOS developers via Xcode project infection, identifying two zero-day exploits (Data Vault SIP bypass, Safari UXSS via WebKit Development) and modules for credential theft, crypto-address replacement, and ransomware capability
  • Trend Micro publishes update detailing browser debug mode abuse and inactive ransomware module in XCSSET
  • XCSSET continues evolving with multiple undisclosed variants during 2020-2022 period
  • Microsoft Threat Intelligence publishes analysis of new XCSSET variant with enhanced obfuscation (randomized xxd/Base64 encoding, 2-5 decoding iterations), three new persistence mechanisms, and C2 domains including bulknames.ru and castlenet.ru
  • Microsoft analyzes further XCSSET evolution: Firefox browser data targeting, clipboard hijacking with crypto-address regex substitution, LaunchDaemon persistence, and run-only compiled AppleScripts for stealth
  • Approximately 40 C2 domains registered in four short bursts from a small IP pool; domains aged for months before activation to bypass new-domain detection; transition from .ru to .in TLDs observed
  • First v40 attack wave observed: supply-chain attacks via compromised Xcode projects on GitHub; 12 C2 domains active; Chrome CDP backdoor (chrome_remote) module deployed; targets macOS developers in South Asia
  • Second v40 attack wave detected: expanded module suite introduces Telegram Desktop trojanizer (tdesktop) module; loader recompiled every few hours with 8 distinct hashes observed for one endpoint in 24 hours
  • Palo Alto Networks Unit 42 publishes comprehensive XCSSET v40 analysis detailing 17-module inventory, dual-key AES-256-CBC encryption architecture, CDP-based fileless reverse shell, and 64 C2 domains
  • Public disclosure of XCSSET v40 campaign reaches mainstream security media; Google confirms extending Chrome CDP abuse protections to macOS

Sources cited for XCSSET v40 macOS Malware Targeting Developers via

Detection coverage for TL-2026-1870

As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1870 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats