Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New XCSSET Malware Variant Targets macOS App Developers

Cybersecurity researchers have identified an advanced variant of the XCSSET malware targeting macOS developers through compromised Xcode projects. This variant introduces enhanced clipboard hijacking and data exfiltration capabilities.

Cybersecurity researchers have identified an advanced variant of the XCSSET malware targeting macOS developers through compromised Xcode projects. This variant introduces enhanced clipboard hijacking and data exfiltration capabilities.

Microsoft Threat Intelligence has observed a new XCSSET variant with additional updates and modules beyond previous versions. The malware infects Xcode projects, commonly used by software developers, executing during the build process.

This variant introduces significant changes in browser targeting, clipboard hijacking, and persistence mechanisms. It employs encryption and obfuscation techniques, runs compiled AppleScripts stealthily, and expands data exfiltration to include Firefox browser data.

The malware also adds persistence through LaunchDaemon entries, complicating detection and removal. A key addition is a module that monitors the clipboard continuously, using a configuration file with regex patterns for digital wallets. Upon detecting a match, XCSSET replaces clipboard content with predefined wallet addresses, hijacking cryptocurrency transactions.

The latest XCSSET variant follows a four-stage infection chain, with the fourth stage introducing new malicious modules. The vexyeqj info-stealer module downloads and executes a compiled AppleScript named "bnk," which performs clipboard monitoring and cryptocurrency wallet hijacking.

This module uses AES encryption with a hardcoded key to decrypt configuration data from command and control servers. The clipboard hijacking functionality checks for cryptocurrency wallet address patterns, verifies applications against a blocklist, and ensures clipboard data differs from previous entries. When conditions are met, legitimate wallet addresses are replaced with attacker-controlled alternatives.

The iewmilh_cdyd module targets Firefox browser data, downloading a modified HackBrowserData project version. This binary extracts passwords, browsing history, credit card information, and cookies from Firefox installations. The extracted data is compressed and exfiltrated to command and control servers in chunks.

The neq_cdyd_ilvcmwx file-stealer module retrieves additional scripts and, like previous wallet data stealers, operates as a compiled AppleScript with enhanced file exfiltration capabilities.

The xmyyeqjx module establishes persistence via LaunchDaemon entries, masquerading as legitimate system processes with plist names using prefixes like "com.google." It also disables macOS automatic configuration updates and Rapid Security Response, weakening system defenses.

Additionally, the jey module maintains Git-based persistence with improved obfuscation. The new version encapsulates decryption logic within shell functions for enhanced stealth.

Security experts recommend several defensive measures against this evolving threat. Organizations should keep operating systems and applications updated, inspect Xcode projects from external sources carefully, and be cautious with clipboard data, especially cryptocurrency addresses.

Cybersecurity researchers have identified an advanced variant of the XCSSET malware targeting macOS developers through compromised Xcode projects.
Jason Ford · Thehackingpost

Microsoft advises using browsers with SmartScreen protection like Microsoft Edge, deploying Microsoft Defender for Endpoint on Mac, and enabling cloud-delivered protection with automatic sample submission. Network protection should be activated to block connections to malicious domains associated with this campaign.

The discovery of this enhanced XCSSET variant highlights its continued evolution and the persistent threat it poses to macOS developers and the broader software supply chain.

Indicator Type Description

cdntor[.]ru Domain C2 server

checkcdn[.]ru Domain C2 server

cdcache[.]ru Domain C2 server

applecdn[.]ru Domain C2 server

flowcdn[.]ru Domain C2 server

elasticdns[.]ru Domain C2 server

Advertisement

rublenet[.]ru Domain C2 server

figmastars[.]ru Domain C2 server

bulksec[.]ru Domain C2 server

dobetrix[.]ru Domain C2 server

figmacat[.]ru Domain C2 server

digichat[.]ru Domain C2 server

diggimax[.]ru Domain C2 server

cdnroute[.]ru Domain C2 server

Follow us on Google News , LinkedIn , and X to Get Instant Updates and Set GBH as a Preferred Source in Google .

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories