XCSSET evolves again: Analyzing the latest updates to XCSSET's inventory

Sept. 25, 2025, 7:06 p.m.

Description

A new variant of the XCSSET malware, designed to infect Xcode projects, has been identified with key changes in browser targeting, clipboard hijacking, and persistence mechanisms. This variant employs sophisticated encryption and obfuscation techniques, uses run-only compiled AppleScripts for stealthy execution, and expands its data exfiltration capabilities to include Firefox browser data. It also adds another persistence mechanism through LaunchDaemon entries. The malware features a submodule for monitoring the clipboard and substituting wallet addresses. The infection chain consists of four stages, with modifications to the boot function and introduction of new modules. Changes include additional checks for Firefox browser, modified logic for Telegram existence check, and new info-stealer modules targeting Firefox data.

Date

  • Created: Sept. 25, 2025, 4:27 p.m.
  • Published: Sept. 25, 2025, 4:27 p.m.
  • Modified: Sept. 25, 2025, 7:06 p.m.

Indicators

  • f3bc158619b2aad17def966f0ac8dddc2107e4911a7c488d358d906f27ac2a2b
  • 5a212c5ce1e0f41e721ce0940afb381b694a2e32a6d19c1d2210f703636362df
  • 12ea52c4089d100e679a2350f03e598b2f3feebfbbd2ed5631a2a7a20b07e826
  • 0fbd0e1995472f308cf1ac8229a02c277035404426769fa50947a72c95ad7d31
  • xcsset.sb
  • xcsset.ba
  • trinitysol.ru
  • windsecure.ru
  • verifysign.ru
  • rublenet.ru
  • sigmanow.ru
  • mdscache.ru
  • flowcdn.ru
  • fixmates.ru
  • figmastars.ru
  • elasticdns.ru
  • figmacat.ru
  • dobetrix.ru
  • dobecdn.ru
  • digitalcdn.ru
  • digichat.ru
  • checkcdn.ru
  • cdntor.ru
  • diggimax.ru
  • bulksec.ru
  • cdnroute.ru
  • cdcache.ru
  • applecdn.ru
  • xcsset.st
  • xcsset.se
  • xcsset.sc

Attack Patterns