Unit 42 researchers have published a deep-dive analysis of XCSSET v40, a new version of the macOS malware family targeting software developers through poisoned Xcode projects and GitHub repositories. Active since April 2026, v40 introduces significant architectural upgrades including polymorphic payload generation, fileless persistence via the macOS defaults system, a dual-key AES encryption scheme, and two new modules: a Chrome DevTools Protocol (CDP)-based browser backdoor and a Telegram Desktop trojanizer. The malware evades detection by running entirely in memory after infection, locking XProtect signature databases, disabling software update channels, resetting TCC permission databases, and reporting VM environments to the C2 to avoid sandbox analysis. Researchers used AI-assisted pattern matching to break the malware's identifier substitution cipher. The C2 infrastructure spans ~40 domains registered in early 2026 across .ru and .in TLDs, with OPSEC failures including shared SSL thumbprints and reused SSH keys across campaigns. Mitigation strategies include behavioral anomaly detection, supply-chain dependency scanning, and monitoring for abnormal defaults domain creation.

22m read timeFrom unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummaryBackgroundInfection Chain AnalysisNew Module BreakdownThe Invisible Malware: New Tactics, Techniques and Procedures (TTPs) BreakdownC2 Infrastructure AnalysisMitigation StrategiesConclusionIndicators of CompromiseAdditional ResourcesAppendix A - XCSSET v40 Infection Lifecycle BreakdownAppendix B - XCSSET V40 Module Breakdown
61 Impressions