s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.xcsset

📛 Threat Title

Malware family: XCSSET

Category: XCSSET First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.xcsset`. Printable name: XCSSET.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.xcsset VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.xcsset

IOC database

Type
domain
Value
osx.xcsset
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.xcsset

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.xcsset

References (1)

Remediations (10)

  • web:adex.com

    Malware Profile: What is XCSSET XCSSET is a modular macOS malware family first discovered in the summer of 2020 that has since undergone significant evolution. It is distributed through compromised Xcode projects and triggered at compile time - the moment a developer builds the project, the malicious payload executes.

  • web:advisory.eventussecurity.com

    macOS malware campaign has been identified, primarily involving the XCSSET malware family , which leverages fake applications, Xcode project infections, and Git hook persistence to compromise developer environments. The attack begins with the vectfd_xhh launcher module, which checks for Xcode or Git installations before deploying its payload.

  • web:attack.mitre.org

    XCSSET is a modular macOS malware family delivered through infected Xcode projects and executed when the project is compiled. Active since August 2020, it has been observed installing backdoors, spoofed browsers, collecting data, and encrypting user files.

  • web:briefglance.com

    Silent Saboteur: XCSSET Malware Infiltrates Apple Developer Tools LIMASSOL, Cyprus - May 19, 2026 - A sophisticated and stealthy malware family is targeting the heart of Apple's software ecosystem, compromising the very tools developers use to create macOS and iOS applications. Security firm ADEX today released a detailed analysis of a live XCSSET malware infection, revealing how it ...

  • web:cybersecuritynews.com

    The macOS threat landscape has witnessed a significant escalation with the discovery of a new variant of the XCSSET malware targeting app developers. First observed in late September 2025, this variant builds upon earlier versions by introducing enhanced stealth techniques, expanded exfiltration capabilities, and robust persistence mechanisms. Attackers continue to leverage infected Xcode ...

  • web:medium.com

    XCSSET is a macOS malware family known for its ability to infect Xcode projects, inject malicious code into applications, and steal sensitive data. It has historically targeted developers and ...

  • web:thehackernews.com

    Microsoft discovers new XCSSET macOS malware variant with enhanced obfuscation, persistence, and infection strategies.

  • web:www.bleepingcomputer.com

    Microsoft Threat Intelligence reports that a new variant of the XCSSET macOS malware has been detected in limited attacks, incorporating several new features, including enhanced browser targeting ...

  • web:www.microsoft.com

    Microsoft Threat Intelligence has uncovered a new variant of XCSSET , a sophisticated modular macOS malware that infects Xcode projects, in the wild. Its first known variant since 2022, this latest XCSSET malware features enhanced obfuscation methods, updated persistence mechanisms, and new infection strategies. These enhanced features help this malware family steal and exfiltrate files and ...

  • web:www.prnewswire.com

    XCSSET is a modular macOS malware family first identified in 2020 that has continued to evolve, with new injection methods documented as recently as 2025 by Microsoft.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.