XCSSET
MITRE ATT&CK: S0658 View on attack.mitre.org
Aliases: OSX.DubRobber, XCSSET
- First seen
- 2020-08-01 00:00:00
- Malware type
- backdoor, ransomware, spyware, trojan
- Family
- Malware family
- Operating systems
- macos
- Related IoCs
- 13 (9 malicious)
- Last IoC activity
- 2026-08-16 14:39:25
- Profile updated
- 2026-07-07 14:35:19
Targeted industries: technology-and-telecommunications media-and-entertainment professional-services
Context
XCSSET is a modular macOS malware family delivered through infected Xcode projects and executed when the project is compiled. Active since August 2020, it has been observed installing backdoors, spoofed browsers, collecting data, and encrypting user files. It is composed of SHC-compiled shell scripts and run-only AppleScripts, often hiding in apps that mimic system tools (such as Xcode, Mail, or Notes) or use familiar icons (like Launchpad) to avoid detection.
Recent IoC activity
8 malicious indicators in Maltiverse are attributed to XCSSET (S0658). The 8 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | sigmate.ru | 2025-10-16 | 2 |
| hostname | rutornet.ru | 2025-10-16 | 2 |
| hostname | castlenet.ru | 2025-10-16 | 2 |
| hostname | figmasol.ru | 2025-10-16 | 2 |
| hostname | trixmate.ru | 2025-10-16 | 2 |
| hostname | itoyads.ru | 2025-10-16 | 2 |
| hostname | gigacells.ru | 2025-10-16 | 2 |
| hostname | bulknames.ru | 2025-10-16 | 2 |
Detection coverage
- 1 YARA rules
- 291 Sigma rules
Malware & tools used
- Hidden Files and Directories (attack-pattern)
- Software Discovery (attack-pattern)
- System Language Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Gatekeeper Bypass (attack-pattern)
- Masquerading (attack-pattern)
- Compromise Software Dependencies and Development Tools (attack-pattern)
- SSH Authorized Keys (attack-pattern)
- Data from Local System (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Dynamic Linker Hijacking (attack-pattern)
- Archive Collected Data (attack-pattern)
- TCC Manipulation (attack-pattern)
- Linux and Mac Permissions (attack-pattern)
- Steal Web Session Cookie (attack-pattern)
- GUI Input Capture (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Launchctl (attack-pattern)
- Security Software Discovery (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- System Information Discovery (attack-pattern)
- Launch Daemon (attack-pattern)
- Plist File Modification (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
Detection rules
- SIGNATURE_BASE_EXT_SUSP_OBFUSC_Macos_Roothelper_Obfuscated (yara-rule)
Reports & references
- objective-see.com — Blog 0X5F (report)
- CrowdStrike — How Crowdstrike Analyzes Macos Malware To Optimize Automated Detection Capabilities (report)
- malpedia.caad.fkie.fraunhofer.de — Osx.Xcsset (report)
- Trend Micro — Xcsset Technical Brief (report)
- Trend Micro — Xcsset Mac Malware Infects Xcode Projects Performs Uxss Attack On Safari Other Browsers Leverages Zero Day Exploits (report)
- Trend Micro — Updated Xcsset Malware Targets Telegram Other Apps (report)
- Kaspersky — 101137 (report)
- jamf.com — Zero Day Tcc Bypass Discovered In Xcsset Malware (report)
- Trend Micro — Xcsset Quickly Adapts To Macos 11 And M1 Based Macs (report)
- MITRE ATT&CK — S0658 (report)
- blog.malwarebytes.com — Osx Dubrobber (report)
- Microsoft — New Xcsset Malware Adds New Obfuscation Persistence Techniques To Infect Xcode Projects (report)
External references
- mitre-attack — S0658
- OSX.DubRobber
- XCSSET
- trendmicro xcsset xcode project 2020
- Microsoft March 2025 XCSSET
- April 2021 TrendMicro XCSSET
- malwarebyteslabs xcsset dubrobber
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy