Last seven days
- First activity
- Sep 9, 2026
- Last activity
- Sep 9, 2026
- Feed role
- C2
- Host form
- 0 IP / 3 hostnames
XCSSET is a modular macOS backdoor and information-stealing malware family targeting Apple software developers through compromised Xcode projects and associated source-code repositories.
Profile source: Mallory opens in a new tabXCSSET
XCSSET is a modular macOS backdoor and information-stealing malware family targeting Apple software developers through compromised Xcode projects and associated source-code repositories. Malicious build rules, scripts, and version-control hooks execute when a poisoned project is built, infecting the developer workstation and propagating into other local Xcode and development projects, creating a downstream software-supply-chain risk. XCSSET has also been observed embedded in a compromised Flutter package example project; dependency use alone did not execute the malicious code.
The malware performs host reconnaissance, including operating-system, user, hardware, locale, firewall, System Integrity Protection, virtual-machine, and security-control checks. It uses hidden artifacts, obfuscated and polymorphic payloads, in-memory execution, short-lived staging components, encrypted command-and-control communications, and repeated loader recompilation to evade detection. Persistence mechanisms observed across variants include malicious Git hooks, Xcode project modifications, shell-profile changes, macOS preference storage, Launch Daemons, Dock-based execution, and trojanized applications. Recent variants also attempt to impair Apple security protections and telemetry, including XProtect, MRT, TCC-related controls, software-update functions, and CloudTelemetryService.
XCSSET collects browser credentials, cookies, session tokens, clipboard contents, screenshots, local files, application data, and data from applications including Safari, Chrome, Firefox, Telegram, Notes, Contacts, Evernote, Opera, Skype, and WeChat. It can use deceptive privilege prompts to obtain access to protected browser data. Newer variants hijack Chrome through the Chrome DevTools Protocol to intercept traffic, execute JavaScript in active sessions, capture autofill data, steal credentials and cookies, manipulate cryptocurrency-wallet transactions, and provide fileless remote command execution. XCSSET can also replace Telegram Desktop with a trojanized application. Collected data is encrypted and exfiltrated over its command-and-control channel. Earlier variants included command-directed file encryption and ransom-note display functionality. Activity has included heightened targeting of developers in South Asia.
C2 tracking
Derp observations, rolling seven-day window
Exploited software
MITRE ATT&CK
Reporting
The Flutter package universal_file_viewer version 0.1.5 was published to pub.dev with XCSSET malware embedded in its example-project files. Its Dart library code was clean, so consuming the package as a dependency does not execute the payload; exposure occurs when developers clone the repository and build the example app locally. The infection appears to have originated from the maintainer's already compromised workstation rather than a targeted takeover of the package or its users. The malicious files inject Android Gradle, Xcode, and Git pre-commit hooks that contact command-and-control infrastructure and can spread to other developer projects. XCSSET is a macOS-focused developer supply-chain malware family that has evolved to steal browser data—including Safari and Firefox credentials, cookies, and history—Telegram, notes, clipboard contents, and local files; it can also replace copied cryptocurrency wallet addresses. The package sample uses disguised Dock-based persistence and AES-256-CBC-encrypted data exfiltration, while recent XCSSET variants have added stronger persistence, stealthy AppleScript-based execution, and expanded Xcode-project propagation.
SMAUG is a ransomware-as-a-service (RaaS) operation that advertises 64-bit payloads for Windows, Linux, and macOS, positioning itself as a multi-platform option for affiliates. The service reportedly charges a 20% affiliate fee plus a 0.2 BTC registration fee, and provides a web-based campaign builder, customizable ransom demands, offline encryption, and a "Company Mode" that allows a single decryption key to unlock multiple systems inside one targeted organization. Victims are directed to a Tor-based payment portal, while operators reportedly offer automated support for both affiliates and victims and bar attacks against CIS countries. On Windows, SMAUG uses obfuscated Go binaries that gather system details and stored browser credentials, establish persistence through Registry Run Keys consistent with MITRE ATT&CK T1547.001, and then encrypt files for impact using AES-256 with keys protected by RSA-2048, aligning with T1486 Data Encrypted for Impact tradecraft. The combination of credential collection, registry-based autostart, and hybrid cryptography reflects a mature ransomware model designed to support repeatable intrusions and broad enterprise targeting across multiple operating systems.
Collector Stealer—also marketed as COLLECTOR Project, CollectorGoomba, and formerly Memory Project—was sold as a Russian-language spyware service and used to steal saved browser credentials, cookies, personal data, screenshots, Telegram and Steam data, and cryptocurrency wallet information from infected Windows systems. Researchers said the malware was spread through phishing portals, fake software downloads, and bundled crack or riskware tools such as KMSAuto, often disguised as miners, game utilities, or activation packages. On infected hosts, it gathered data from browsers and applications, captured screenshots, scanned directories, extracted SQLite-stored information, and staged the loot in ZIP or RAR archives before sending it to attacker-controlled panels over HTTP POST. Analysis of the malware’s infrastructure showed that some builds fetched their command-and-control destination from a text file hosted on GitHub, with a fallback to a hard-coded justns.ru subdomain if retrieval failed. After the malicious GitHub repository was reported and removed, affected samples attempted to exfiltrate to an invalid 404: Not Found.ru destination and crashed, temporarily disrupting those variants. Operators later updated newer samples to use upaste[.]me for C2 redirection instead, indicating the stealer remained under active development and continued to evolve its exfiltration workflow and delivery ecosystem.
A U.S. federal jury convicted Russian national Oleg Koshkin for operating malware crypter services that helped the Kelihos botnet evade antivirus detection and spread malicious payloads. Prosecutors said Koshkin ran sites including Crypt4U.com, Crypt4U.net, fud.bz, and fud.re, advertising tools that made malware such as botnets, RATs, keyloggers, stealers, crypto miners, and ransomware fully undetectable. Court evidence showed Kelihos operator Peter Levashov paid roughly $3,000 per month from 2014 to 2017 for custom high-volume re-crypting, while co-defendant Pavel Tsurkan pleaded guilty to aiding malware infections worldwide, including ransomware attacks. The conviction builds on the broader U.S. campaign against Kelihos, a botnet active since at least 2010 that at various points controlled 60,000 to more than 100,000 compromised Windows computers. Authorities said the botnet was used for spam, credential theft, pump-and-dump stock fraud, denial-of-service activity, and malware distribution before the FBI and partners including CrowdStrike and the Shadowserver Foundation disrupted it through a sinkholing operation and Levashov’s arrest in Spain. Investigators linked Levashov to the infrastructure through IP and account records, with reporting noting operational security mistakes such as reused credentials that helped expose him.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.