Mac Threat Response, Mobile Research Team. (2020, August 13). The XCSSET Malware: Inserts Malicious Code Into Xcode Projects, Performs UXSS Backdoor Planting in Safari, and Leverages Two Zero-day Exploits. Retrieved October 5, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareXCSSET | XCSSET collects contacts and application data from files in Desktop, Documents, Downloads, Dropbox, and WeChat folders. |
| T1036 Masquerading |
MalwareXCSSET | XCSSET installs malicious application bundles that mimic native macOS apps, such as Safari, by using the legitimate app’s icon and customizing the `Info.plist` to match expected metadata. |
| T1041 Exfiltration Over C2 Channel |
MalwareXCSSET | XCSSET retrieves files that match the pattern defined in the INAME_QUERY variable within the user's home directory, such as `*test.txt`, and are below a specific size limit. It then archives the files and exfiltrates the data over its C2 channel. |
| T1056.002 GUI Input Capture |
MalwareXCSSET | XCSSET prompts the user to input credentials using a native macOS dialog box leveraging the system process |
| T1059.004 Unix Shell |
MalwareXCSSET | XCSSET uses a shell script to execute Mach-o files and |
| T1068 Exploitation for Privilege Escalation |
MalwareXCSSET | XCSSET has used a zero-day exploit in the ssh launchdaemon to elevate privileges and bypass SIP. |
| T1082 System Information Discovery |
MalwareXCSSET | XCSSET identifies the macOS version and uses |
| T1087 Account Discovery |
MalwareXCSSET | XCSSET attempts to discover accounts from various locations such as a user's Evernote, AppleID, Telegram, Skype, and WeChat data. |
| T1098.004 SSH Authorized Keys |
MalwareXCSSET | XCSSET will create an ssh key if necessary with the |
| T1105 Ingress Tool Transfer |
MalwareXCSSET | XCSSET downloads browser specific AppleScript modules using a constructed URL with the |
| T1113 Screen Capture |
MalwareXCSSET | XCSSET saves a screen capture of the victim's system with a numbered filename and |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareXCSSET | XCSSET adds malicious code to a host's Xcode projects by enumerating CocoaPods |
| T1486 Data Encrypted for Impact |
MalwareXCSSET | XCSSET performs AES-CBC encryption on files under |
| T1497.003 Time Based Checks |
MalwareXCSSET | Using the machine's local time, XCSSET waits 43200 seconds (12 hours) from the initial creation timestamp of a specific file, |
| T1518 Software Discovery |
MalwareXCSSET | XCSSET uses |
| T1518.001 Security Software Discovery |
MalwareXCSSET | XCSSET searches firewall configuration files located in |
| T1539 Steal Web Session Cookie |
MalwareXCSSET | XCSSET uses |
| T1543.004 Launch Daemon |
MalwareXCSSET | XCSSET uses the ssh launchdaemon to elevate privileges, bypass system controls, and enable remote access to the victim. |
| T1554 Compromise Host Software Binary |
MalwareXCSSET | XCSSET uses a malicious browser application to replace the legitimate browser in order to continuously capture credentials, monitor web traffic, and download additional modules. |
| T1560 Archive Collected Data |
MalwareXCSSET | XCSSET will compress entire |
| T1564.001 Hidden Files and Directories |
MalwareXCSSET | XCSSET uses a hidden folder named |
| T1569.001 Launchctl |
MalwareXCSSET | XCSSET loads a system level launchdaemon using the |
| T1573.001 Symmetric Cryptography |
MalwareXCSSET | XCSSET uses RC4 encryption over TCP to communicate with its C2 server. |
| T1574.006 Dynamic Linker Hijacking |
MalwareXCSSET | XCSSET adds malicious file paths to the |
| T1614.001 System Language Discovery |
MalwareXCSSET | XCSSET uses AppleScript to check the host's language and location with the command |
| T1647 Plist File Modification |
MalwareXCSSET | In older versions, XCSSET uses the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.