TF-MAL-osx.xcsset
📛 Threat Title
Malware family: XCSSET
Description
ThreatFox malware family `osx.xcsset`. Printable name: XCSSET.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.xcsset
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.xcsset
IOC database
- Type
- domain
- Value
osx.xcsset- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.xcsset
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.xcsset
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:adex.com
Malware Profile: What is XCSSET XCSSET is a modular macOS malware family first discovered in the summer of 2020 that has since undergone significant evolution. It is distributed through compromised Xcode projects and triggered at compile time - the moment a developer builds the project, the malicious payload executes.
-
web:advisory.eventussecurity.com
macOS malware campaign has been identified, primarily involving the XCSSET malware family , which leverages fake applications, Xcode project infections, and Git hook persistence to compromise developer environments. The attack begins with the vectfd_xhh launcher module, which checks for Xcode or Git installations before deploying its payload.
-
web:attack.mitre.org
XCSSET is a modular macOS malware family delivered through infected Xcode projects and executed when the project is compiled. Active since August 2020, it has been observed installing backdoors, spoofed browsers, collecting data, and encrypting user files.
-
web:briefglance.com
Silent Saboteur: XCSSET Malware Infiltrates Apple Developer Tools LIMASSOL, Cyprus - May 19, 2026 - A sophisticated and stealthy malware family is targeting the heart of Apple's software ecosystem, compromising the very tools developers use to create macOS and iOS applications. Security firm ADEX today released a detailed analysis of a live XCSSET malware infection, revealing how it ...
-
web:cybersecuritynews.com
The macOS threat landscape has witnessed a significant escalation with the discovery of a new variant of the XCSSET malware targeting app developers. First observed in late September 2025, this variant builds upon earlier versions by introducing enhanced stealth techniques, expanded exfiltration capabilities, and robust persistence mechanisms. Attackers continue to leverage infected Xcode ...
-
web:medium.com
XCSSET is a macOS malware family known for its ability to infect Xcode projects, inject malicious code into applications, and steal sensitive data. It has historically targeted developers and ...
-
web:thehackernews.com
Microsoft discovers new XCSSET macOS malware variant with enhanced obfuscation, persistence, and infection strategies.
-
web:www.bleepingcomputer.com
Microsoft Threat Intelligence reports that a new variant of the XCSSET macOS malware has been detected in limited attacks, incorporating several new features, including enhanced browser targeting ...
-
web:www.microsoft.com
Microsoft Threat Intelligence has uncovered a new variant of XCSSET , a sophisticated modular macOS malware that infects Xcode projects, in the wild. Its first known variant since 2022, this latest XCSSET malware features enhanced obfuscation methods, updated persistence mechanisms, and new infection strategies. These enhanced features help this malware family steal and exfiltrate files and ...
-
web:www.prnewswire.com
XCSSET is a modular macOS malware family first identified in 2020 that has continued to evolve, with new injection methods documented as recently as 2025 by Microsoft.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.