ATT&CKReferencestrendmicro xcsset xcode project 2020

trendmicro xcsset xcode project 2020

Mac Threat Response, Mobile Research Team. (2020, August 13). The XCSSET Malware: Inserts Malicious Code Into Xcode Projects, Performs UXSS Backdoor Planting in Safari, and Leverages Two Zero-day Exploits. Retrieved October 5, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples26

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareXCSSET

XCSSET collects contacts and application data from files in Desktop, Documents, Downloads, Dropbox, and WeChat folders.

T1036
Masquerading
MalwareXCSSET

XCSSET installs malicious application bundles that mimic native macOS apps, such as Safari, by using the legitimate app’s icon and customizing the `Info.plist` to match expected metadata.

T1041
Exfiltration Over C2 Channel
MalwareXCSSET

XCSSET retrieves files that match the pattern defined in the INAME_QUERY variable within the user's home directory, such as `*test.txt`, and are below a specific size limit. It then archives the files and exfiltrates the data over its C2 channel.

T1056.002
GUI Input Capture
MalwareXCSSET

XCSSET prompts the user to input credentials using a native macOS dialog box leveraging the system process /Applications/Safari.app/Contents/MacOS/SafariForWebKitDevelopment.

T1059.004
Unix Shell
MalwareXCSSET

XCSSET uses a shell script to execute Mach-o files and osacompile commands such as, osacompile -x -o xcode.app main.applescript.

T1068
Exploitation for Privilege Escalation
MalwareXCSSET

XCSSET has used a zero-day exploit in the ssh launchdaemon to elevate privileges and bypass SIP.

T1082
System Information Discovery
MalwareXCSSET

XCSSET identifies the macOS version and uses ioreg to determine serial number.

T1087
Account Discovery
MalwareXCSSET

XCSSET attempts to discover accounts from various locations such as a user's Evernote, AppleID, Telegram, Skype, and WeChat data.

T1098.004
SSH Authorized Keys
MalwareXCSSET

XCSSET will create an ssh key if necessary with the ssh-keygen -t rsa -f $HOME/.ssh/id_rsa -P command. XCSSET will upload a private key file to the server to remotely access the host without a password.

T1105
Ingress Tool Transfer
MalwareXCSSET

XCSSET downloads browser specific AppleScript modules using a constructed URL with the curl command, https://" & domain & "/agent/scripts/" & moduleName & ".applescript.

T1113
Screen Capture
MalwareXCSSET

XCSSET saves a screen capture of the victim's system with a numbered filename and .jpg extension. Screen captures are taken at specified intervals based on the system.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareXCSSET

XCSSET adds malicious code to a host's Xcode projects by enumerating CocoaPods target_integrator.rb files under the /Library/Ruby/Gems folder or enumerates all .xcodeproj folders under a given directory. XCSSET then downloads a script and Mach-O file into the Xcode project folder.

T1486
Data Encrypted for Impact
MalwareXCSSET

XCSSET performs AES-CBC encryption on files under ~/Documents, ~/Downloads, and
~/Desktop with a fixed key and renames files to give them a .enc extension. Only files with sizes
less than 500MB are encrypted.

T1497.003
Time Based Checks
MalwareXCSSET

Using the machine's local time, XCSSET waits 43200 seconds (12 hours) from the initial creation timestamp of a specific file, .report. After the elapsed time, XCSSET executes additional modules.

T1518
Software Discovery
MalwareXCSSET

XCSSET uses ps aux with the grep command to enumerate common browsers and system processes potentially impacting XCSSET's exfiltration capabilities.

T1518.001
Security Software Discovery
MalwareXCSSET

XCSSET searches firewall configuration files located in /Library/Preferences/ and uses csrutil status to determine if System Integrity Protection is enabled.

T1539
Steal Web Session Cookie
MalwareXCSSET

XCSSET uses scp to access the ~/Library/Cookies/Cookies.binarycookies file.

T1543.004
Launch Daemon
MalwareXCSSET

XCSSET uses the ssh launchdaemon to elevate privileges, bypass system controls, and enable remote access to the victim.

T1554
Compromise Host Software Binary
MalwareXCSSET

XCSSET uses a malicious browser application to replace the legitimate browser in order to continuously capture credentials, monitor web traffic, and download additional modules.

T1560
Archive Collected Data
MalwareXCSSET

XCSSET will compress entire ~/Desktop folders excluding all .git folders, but only if the total data size is under 200MB.

T1564.001
Hidden Files and Directories
MalwareXCSSET

XCSSET uses a hidden folder named .xcassets and .git to embed itself in Xcode.

T1569.001
Launchctl
MalwareXCSSET

XCSSET loads a system level launchdaemon using the launchctl load -w command from /System/Librarby/LaunchDaemons/ssh.plist.

T1573.001
Symmetric Cryptography
MalwareXCSSET

XCSSET uses RC4 encryption over TCP to communicate with its C2 server.

T1574.006
Dynamic Linker Hijacking
MalwareXCSSET

XCSSET adds malicious file paths to the DYLD_FRAMEWORK_PATH and DYLD_LIBRARY_PATH environment variables to execute malicious code.

T1614.001
System Language Discovery
MalwareXCSSET

XCSSET uses AppleScript to check the host's language and location with the command user locale of (get system info).

T1647
Plist File Modification
MalwareXCSSET

In older versions, XCSSET uses the plutil command to modify the LSUIElement, DFBundleDisplayName, and CFBundleIdentifier keys in the /Contents/Info.plist file to change how XCSSET is visible on the system. In later versions, XCSSET leverages a third-party notarized `dockutil` tool to modify the `.plist` file responsible for presenting applications to the user in the Dock and LaunchPad to point to a malicious application.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.