New XCSSET Malware Variant Targets macOS App Developers
Cybersecurity researchers have identified an advanced variant of the XCSSET malware targeting macOS developers through compromised Xcode projects. This variant introduces enhanced clipboard hijacking and data exfiltration capabilities.
Cybersecurity researchers have identified an advanced variant of the XCSSET malware targeting macOS developers through compromised Xcode projects. This variant introduces enhanced clipboard hijacking and data exfiltration capabilities.
Microsoft Threat Intelligence has observed a new XCSSET variant with additional updates and modules beyond previous versions. The malware infects Xcode projects, commonly used by software developers, executing during the build process.
This variant introduces significant changes in browser targeting, clipboard hijacking, and persistence mechanisms. It employs encryption and obfuscation techniques, runs compiled AppleScripts stealthily, and expands data exfiltration to include Firefox browser data.
The malware also adds persistence through LaunchDaemon entries, complicating detection and removal. A key addition is a module that monitors the clipboard continuously, using a configuration file with regex patterns for digital wallets. Upon detecting a match, XCSSET replaces clipboard content with predefined wallet addresses, hijacking cryptocurrency transactions.
The latest XCSSET variant follows a four-stage infection chain, with the fourth stage introducing new malicious modules. The vexyeqj info-stealer module downloads and executes a compiled AppleScript named "bnk," which performs clipboard monitoring and cryptocurrency wallet hijacking.
This module uses AES encryption with a hardcoded key to decrypt configuration data from command and control servers. The clipboard hijacking functionality checks for cryptocurrency wallet address patterns, verifies applications against a blocklist, and ensures clipboard data differs from previous entries. When conditions are met, legitimate wallet addresses are replaced with attacker-controlled alternatives.
The iewmilh_cdyd module targets Firefox browser data, downloading a modified HackBrowserData project version. This binary extracts passwords, browsing history, credit card information, and cookies from Firefox installations. The extracted data is compressed and exfiltrated to command and control servers in chunks.
The neq_cdyd_ilvcmwx file-stealer module retrieves additional scripts and, like previous wallet data stealers, operates as a compiled AppleScript with enhanced file exfiltration capabilities.
The xmyyeqjx module establishes persistence via LaunchDaemon entries, masquerading as legitimate system processes with plist names using prefixes like "com.google." It also disables macOS automatic configuration updates and Rapid Security Response, weakening system defenses.
Additionally, the jey module maintains Git-based persistence with improved obfuscation. The new version encapsulates decryption logic within shell functions for enhanced stealth.
Security experts recommend several defensive measures against this evolving threat. Organizations should keep operating systems and applications updated, inspect Xcode projects from external sources carefully, and be cautious with clipboard data, especially cryptocurrency addresses.
Cybersecurity researchers have identified an advanced variant of the XCSSET malware targeting macOS developers through compromised Xcode projects.
Microsoft advises using browsers with SmartScreen protection like Microsoft Edge, deploying Microsoft Defender for Endpoint on Mac, and enabling cloud-delivered protection with automatic sample submission. Network protection should be activated to block connections to malicious domains associated with this campaign.
The discovery of this enhanced XCSSET variant highlights its continued evolution and the persistent threat it poses to macOS developers and the broader software supply chain.
Indicator Type Description
cdntor[.]ru Domain C2 server
checkcdn[.]ru Domain C2 server
cdcache[.]ru Domain C2 server
applecdn[.]ru Domain C2 server
flowcdn[.]ru Domain C2 server
elasticdns[.]ru Domain C2 server
rublenet[.]ru Domain C2 server
figmastars[.]ru Domain C2 server
bulksec[.]ru Domain C2 server
dobetrix[.]ru Domain C2 server
figmacat[.]ru Domain C2 server
digichat[.]ru Domain C2 server
diggimax[.]ru Domain C2 server
cdnroute[.]ru Domain C2 server
Follow us on Google News , LinkedIn , and X to Get Instant Updates and Set GBH as a Preferred Source in Google .
Based on reporting by GBHackers.
