logo

The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

ID: 76f6f514-deac-51d6-92b0-f2a8f46a49e3

STIX ID: report--76f6f514-deac-51d6-92b0-f2a8f46a49e3

Feed Name: Palo Alto Networks Unit 42

Threat Score
88/100

Date Published: 2026-07-31

Date Updated: 2026-07-31

Author: Adva Gabay and Noa Dekel

...
...

This report analyzes XCSSET v40, a renewed and more stealthy macOS malware campaign that propagates through trojanized Xcode projects and vulnerable Git repositories; v40 employs fileless, in-memory execution, multi-layered polymorphic encryption, new browser-hijacking (chrome_remote) and Telegram-trojanizer modules, and an evolving C2 infrastructure with numerous domains and IPs, and provides detailed mitigation guidance and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.