logo

New XCSSET malware adds new obfuscation, persistence techniques to infect Xcode projects

ID: e6b477d2-c057-50a0-aaf3-a53c37ae2a29

STIX ID: report--e6b477d2-c057-50a0-aaf3-a53c37ae2a29

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2025-03-11

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence describes a new modular XCSSET macOS malware variant that infects Xcode projects and uses multi-stage obfuscated shell and AppleScript payloads to establish persistence (zshrc, fake Launchpad via Dock, Git pre-commit), steal data (browser wallet extensions, Notes, system/browser info), and download additional modules from active C2 domains; the blog provides technical analysis of stages and submodules, IOCs, MITRE ATT&CK mappings, hunting queries, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.