XCSSET

MITRE ATT&CK: S0658 View on attack.mitre.org

Aliases: OSX.DubRobber, XCSSET

First seen
2020-08-01 00:00:00
Malware type
backdoor, ransomware, spyware, trojan
Family
Malware family
Operating systems
macos
Related IoCs
13 (9 malicious)
Last IoC activity
2026-08-16 14:39:25
Profile updated
2026-07-07 14:35:19

Targeted industries: technology-and-telecommunications media-and-entertainment professional-services

Context

XCSSET is a modular macOS malware family delivered through infected Xcode projects and executed when the project is compiled. Active since August 2020, it has been observed installing backdoors, spoofed browsers, collecting data, and encrypting user files. It is composed of SHC-compiled shell scripts and run-only AppleScripts, often hiding in apps that mimic system tools (such as Xcode, Mail, or Notes) or use familiar icons (like Launchpad) to avoid detection.

Recent IoC activity

8 malicious indicators in Maltiverse are attributed to XCSSET (S0658). The 8 most recently updated:

TypeIndicatorUpdatedSources
hostname sigmate.ru 2025-10-16 2
hostname rutornet.ru 2025-10-16 2
hostname castlenet.ru 2025-10-16 2
hostname figmasol.ru 2025-10-16 2
hostname trixmate.ru 2025-10-16 2
hostname itoyads.ru 2025-10-16 2
hostname gigacells.ru 2025-10-16 2
hostname bulknames.ru 2025-10-16 2

Detection coverage

  • 1 YARA rules
  • 291 Sigma rules

Malware & tools used

  • Hidden Files and Directories (attack-pattern)
  • Software Discovery (attack-pattern)
  • System Language Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Gatekeeper Bypass (attack-pattern)
  • Masquerading (attack-pattern)
  • Compromise Software Dependencies and Development Tools (attack-pattern)
  • SSH Authorized Keys (attack-pattern)
  • Data from Local System (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Dynamic Linker Hijacking (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • TCC Manipulation (attack-pattern)
  • Linux and Mac Permissions (attack-pattern)
  • Steal Web Session Cookie (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Launchctl (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Launch Daemon (attack-pattern)
  • Plist File Modification (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)

Detection rules

  • SIGNATURE_BASE_EXT_SUSP_OBFUSC_Macos_Roothelper_Obfuscated (yara-rule)

Reports & references

  • objective-see.com — Blog 0X5F (report)
  • CrowdStrike — How Crowdstrike Analyzes Macos Malware To Optimize Automated Detection Capabilities (report)
  • malpedia.caad.fkie.fraunhofer.de — Osx.Xcsset (report)
  • Trend Micro — Xcsset Technical Brief (report)
  • Trend Micro — Xcsset Mac Malware Infects Xcode Projects Performs Uxss Attack On Safari Other Browsers Leverages Zero Day Exploits (report)
  • Trend Micro — Updated Xcsset Malware Targets Telegram Other Apps (report)
  • Kaspersky — 101137 (report)
  • jamf.com — Zero Day Tcc Bypass Discovered In Xcsset Malware (report)
  • Trend Micro — Xcsset Quickly Adapts To Macos 11 And M1 Based Macs (report)
  • MITRE ATT&CK — S0658 (report)
  • blog.malwarebytes.com — Osx Dubrobber (report)
  • Microsoft — New Xcsset Malware Adds New Obfuscation Persistence Techniques To Infect Xcode Projects (report)

External references