Malware.View on attack.mitre.org
XCSSET is a modular macOS malware family delivered through infected Xcode projects and executed when the project is compiled. Active since August 2020, it has been observed installing backdoors, spoofed browsers, collecting data, and encrypting user files. It is composed of SHC-compiled shell scripts and run-only AppleScripts, often hiding in apps that mimic system tools (such as Xcode, Mail, or Notes) or use familiar icons (like Launchpad) to avoid detection.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
XCSSET collects contacts and application data from files in Desktop, Documents, Downloads, Dropbox, and WeChat folders. |
| T1027.013 Encrypted/Encoded File |
Older XCSSET variants use `xxd` to encode modules. Later versions pass an `xxd` or `base64` encoded blob through multiple decoding stages to reconstruct the module name, AppleScript, or shell command. For example, the initial network request uses three layers of hex decoding before executing a curl command in a shell. |
| T1036 Masquerading |
XCSSET installs malicious application bundles that mimic native macOS apps, such as Safari, by using the legitimate app’s icon and customizing the `Info.plist` to match expected metadata. |
| T1041 Exfiltration Over C2 Channel |
XCSSET retrieves files that match the pattern defined in the INAME_QUERY variable within the user's home directory, such as `*test.txt`, and are below a specific size limit. It then archives the files and exfiltrates the data over its C2 channel. |
| T1056.002 GUI Input Capture |
XCSSET prompts the user to input credentials using a native macOS dialog box leveraging the system process |
| T1059.004 Unix Shell |
XCSSET uses a shell script to execute Mach-o files and |
| T1068 Exploitation for Privilege Escalation |
XCSSET has used a zero-day exploit in the ssh launchdaemon to elevate privileges and bypass SIP. |
| T1082 System Information Discovery |
XCSSET identifies the macOS version and uses |
| T1083 File and Directory Discovery |
XCSSET has used `mdfind` to enumerate a list of apps known to grant screen sharing permissions and leverages a module to run the command `ls -la ~/Desktop`. |
| T1087 Account Discovery |
XCSSET attempts to discover accounts from various locations such as a user's Evernote, AppleID, Telegram, Skype, and WeChat data. |
| T1098.004 SSH Authorized Keys |
XCSSET will create an ssh key if necessary with the |
| T1105 Ingress Tool Transfer |
XCSSET downloads browser specific AppleScript modules using a constructed URL with the |
| T1113 Screen Capture |
XCSSET saves a screen capture of the victim's system with a numbered filename and |
| T1195.001 Compromise Software Dependencies and Development Tools |
XCSSET adds malicious code to a host's Xcode projects by enumerating CocoaPods |
| T1222.002 Linux and Mac Permissions |
XCSSET uses the |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.