Skip to content

XCSSET

XCSSET is a modular macOS backdoor and information-stealing malware family targeting Apple software developers through compromised Xcode projects and associated source-code repositories.

Profile source: Mallory opens in a new tab

XCSSET

Family profile

XCSSET is a modular macOS backdoor and information-stealing malware family targeting Apple software developers through compromised Xcode projects and associated source-code repositories. Malicious build rules, scripts, and version-control hooks execute when a poisoned project is built, infecting the developer workstation and propagating into other local Xcode and development projects, creating a downstream software-supply-chain risk. XCSSET has also been observed embedded in a compromised Flutter package example project; dependency use alone did not execute the malicious code.

The malware performs host reconnaissance, including operating-system, user, hardware, locale, firewall, System Integrity Protection, virtual-machine, and security-control checks. It uses hidden artifacts, obfuscated and polymorphic payloads, in-memory execution, short-lived staging components, encrypted command-and-control communications, and repeated loader recompilation to evade detection. Persistence mechanisms observed across variants include malicious Git hooks, Xcode project modifications, shell-profile changes, macOS preference storage, Launch Daemons, Dock-based execution, and trojanized applications. Recent variants also attempt to impair Apple security protections and telemetry, including XProtect, MRT, TCC-related controls, software-update functions, and CloudTelemetryService.

XCSSET collects browser credentials, cookies, session tokens, clipboard contents, screenshots, local files, application data, and data from applications including Safari, Chrome, Firefox, Telegram, Notes, Contacts, Evernote, Opera, Skype, and WeChat. It can use deceptive privilege prompts to obtain access to protected browser data. Newer variants hijack Chrome through the Chrome DevTools Protocol to intercept traffic, execute JavaScript in active sessions, capture autofill data, steal credentials and cookies, manipulate cryptocurrency-wallet transactions, and provide fileless remote command execution. XCSSET can also replace Telegram Desktop with a trojanized application. Collected data is encrypted and exfiltrated over its command-and-control channel. Earlier variants included command-directed file encryption and ransom-note display functionality. Activity has included heightened targeting of developers in South Asia.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Keylogging
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance
  • Session Hijacking
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 9, 2026
Last activity
Sep 9, 2026
Feed role
C2
Host form
0 IP / 3 hostnames

Leading locations

  • DE3

Leading providers

  • Regxa Company for Information Technology Ltd3

Infrastructure traits

  • Hosting 3

Exploited software

Vulnerabilities linked to XCSSET

1 CVEs

MITRE ATT&CK

XCSSET in ATT&CK

77 distinct techniques

Techniques

77 techniques
T1195 Supply Chain Compromise T1033 System Owner/User Discovery T1620 Reflective Code Loading T1083 File and Directory Discovery T1082 System Information Discovery T1027 Obfuscated Files or Information T1036.005 Match Legitimate Resource Name or Location T1548.003 Sudo and Sudo Caching T1547 Boot or Logon Autostart Execution T1560 Archive Collected Data T1071.001 Web Protocols T1059.002 AppleScript T1546 Event Triggered Execution T1115 Clipboard Data T1005 Data from Local System T1539 Steal Web Session Cookie T1041 Exfiltration Over C2 Channel T1555.003 Credentials from Web Browsers T1059.004 Unix Shell T1105 Ingress Tool Transfer T1059.007 JavaScript T1113 Screen Capture T1555 Credentials from Password Stores T1071 Application Layer Protocol T1486 Data Encrypted for Impact T1212 Exploitation for Credential Access T1059 Command and Scripting Interpreter T1056 Input Capture T1518.001 Security Software Discovery T1564.001 Hidden Files and Directories T1573 Encrypted Channel T1095 Non-Application Layer Protocol T1036 Masquerading T1195.001 Compromise Software Dependencies and Development Tools T1649 Steal or Forge Authentication Certificates T1204 User Execution T1548 Abuse Elevation Control Mechanism T1027.013 Encrypted/Encoded File T1574 Hijack Execution Flow T1070 Indicator Removal T1562 Impair Defenses T1056.001 Keylogging T1185 Browser Session Hijacking T1219 Remote Access Tools T1565 Data Manipulation T1204.002 Malicious File T1556 Modify Authentication Process T1027.014 Polymorphic Code T1056.003 Web Portal Capture T1543.004 Launch Daemon T1140 Deobfuscate/Decode Files or Information T1546.004 Unix Shell Configuration Modification T1497 Virtualization/Sandbox Evasion T1574.013 KernelCallbackTable T1070.004 File Deletion T1614.001 System Language Discovery T1574.001 DLL T1211 Exploitation for Defense Evasion T1526 Cloud Service Discovery T1518 Software Discovery T1119 Automated Collection T1068 Exploitation for Privilege Escalation T1053.003 Cron T1056.002 GUI Input Capture T1057 Process Discovery T1562.001 Disable or Modify Tools T1574.006 Dynamic Linker Hijacking T1497.003 Time Based Checks T1553.001 Gatekeeper Bypass T1087 Account Discovery T1548.006 TCC Manipulation T1098.004 SSH Authorized Keys T1569.001 Launchctl T1647 Plist File Modification T1554 Compromise Host Software Binary T1573.001 Symmetric Cryptography T1222.002 Linux and Mac File and Directory Permissions Modification

Reporting

Research mentioning XCSSET

Sep 8
Aikido Dev

Compromised Flutter package on pub.dev contains XCSSET malware

The Flutter package universal_file_viewer version 0.1.5 was published to pub.dev with XCSSET malware embedded in its example-project files. Its Dart library code was clean, so consuming the package as a dependency does not execute the payload; exposure occurs when developers clone the repository and build the example app locally. The infection appears to have originated from the maintainer's already compromised workstation rather than a targeted takeover of the package or its users. The malicious files inject Android Gradle, Xcode, and Git pre-commit hooks that contact command-and-control infrastructure and can spread to other developer projects. XCSSET is a macOS-focused developer supply-chain malware family that has evolved to steal browser data—including Safari and Firefox credentials, cookies, and history—Telegram, notes, clipboard contents, and local files; it can also replace copied cryptocurrency wallet addresses. The package sample uses disguised Dock-based persistence and AES-256-CBC-encrypted data exfiltration, while recent XCSSET variants have added stronger persistence, stealthy AppleScript-based execution, and expanded Xcode-project propagation.

Mar 22
Sentinelone Labs Subdomain

Multi-Platform SMAUG RaaS Aims To See Off Competitors - SentinelLabs

SMAUG is a ransomware-as-a-service (RaaS) operation that advertises 64-bit payloads for Windows, Linux, and macOS, positioning itself as a multi-platform option for affiliates. The service reportedly charges a 20% affiliate fee plus a 0.2 BTC registration fee, and provides a web-based campaign builder, customizable ransom demands, offline encryption, and a "Company Mode" that allows a single decryption key to unlock multiple systems inside one targeted organization. Victims are directed to a Tor-based payment portal, while operators reportedly offer automated support for both affiliates and victims and bar attacks against CIS countries. On Windows, SMAUG uses obfuscated Go binaries that gather system details and stored browser credentials, establish persistence through Registry Run Keys consistent with MITRE ATT&CK T1547.001, and then encrypt files for impact using AES-256 with keys protected by RSA-2048, aligning with T1486 Data Encrypted for Impact tradecraft. The combination of credential collection, registry-based autostart, and hybrid cryptography reflects a mature ransomware model designed to support repeatable intrusions and broad enterprise targeting across multiple operating systems.

Dec 1
Virusbulletin

Virus Bulletin :: Collector-stealer: a Russian origin credential and information extractor

Collector Stealer—also marketed as COLLECTOR Project, CollectorGoomba, and formerly Memory Project—was sold as a Russian-language spyware service and used to steal saved browser credentials, cookies, personal data, screenshots, Telegram and Steam data, and cryptocurrency wallet information from infected Windows systems. Researchers said the malware was spread through phishing portals, fake software downloads, and bundled crack or riskware tools such as KMSAuto, often disguised as miners, game utilities, or activation packages. On infected hosts, it gathered data from browsers and applications, captured screenshots, scanned directories, extracted SQLite-stored information, and staged the loot in ZIP or RAR archives before sending it to attacker-controlled panels over HTTP POST. Analysis of the malware’s infrastructure showed that some builds fetched their command-and-control destination from a text file hosted on GitHub, with a fallback to a hard-coded justns.ru subdomain if retrieval failed. After the malicious GitHub repository was reported and removed, affected samples attempted to exfiltrate to an invalid 404: Not Found.ru destination and crashed, temporarily disrupting those variants. Operators later updated newer samples to use upaste[.]me for C2 redirection instead, indicating the stealer remained under active development and continued to evolve its exfiltration workflow and delivery ecosystem.

Jun 16
Us Department Of Justice

Office of Public Affairs | Russian National Convicted of Charges Relating to Kelihos Botnet | United States Department of Justice

A U.S. federal jury convicted Russian national Oleg Koshkin for operating malware crypter services that helped the Kelihos botnet evade antivirus detection and spread malicious payloads. Prosecutors said Koshkin ran sites including Crypt4U.com, Crypt4U.net, fud.bz, and fud.re, advertising tools that made malware such as botnets, RATs, keyloggers, stealers, crypto miners, and ransomware fully undetectable. Court evidence showed Kelihos operator Peter Levashov paid roughly $3,000 per month from 2014 to 2017 for custom high-volume re-crypting, while co-defendant Pavel Tsurkan pleaded guilty to aiding malware infections worldwide, including ransomware attacks. The conviction builds on the broader U.S. campaign against Kelihos, a botnet active since at least 2010 that at various points controlled 60,000 to more than 100,000 compromised Windows computers. Authorities said the botnet was used for spam, credential theft, pump-and-dump stock fraud, denial-of-service activity, and malware distribution before the FBI and partners including CrowdStrike and the Shadowserver Foundation disrupted it through a sinkholing operation and Levashov’s arrest in Spain. Investigators linked Levashov to the infrastructure through IP and account records, with reporting noting operational security mistakes such as reused credentials that helped expose him.

Jun 16
Bleeping Computer

US convicts Russian national behind Kelihos botnet crypting service

Jul 1
Vmray

Cutting-off the Command-and-Control Infrastructure of CollectorGoomba | Threat Bulletin | VMRay

Apr 11
Wired Com Security

How Russian Spam King Peter Levashov Was Arrested, and His Kelihos Botnet Dismantled | WIRED

Apr 10
Cyberscoop

DOJ moves to topple Kelihos, one of the world's largest botnets - CyberScoop

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.