XCSSET v40 is a modular macOS malware targeting software developers through infected Xcode projects. It features advanced stealth techniques including fileless persistence via the macOS defaults system, multi-layered polymorphism, and active impairment of macOS security mechanisms like XProtect and TCC. New operational modules include a Chrome DevTools Protocol (CDP) hijacker for browser manipulation and a Telegram trojanizer for persistent access.
Polymorphism
1 post
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version