THE latest deployment of XCSSET malware version 40 (v40) targets macOS, utilizing advanced techniques to evade detection and perpetuate infections through supply chain attacks. The malware operates by embedding itself in legitimate Xcode projects, which are widely used by developers, and employs fileless persistence, dynamic memory execution, and multi-layered encryption to obscure its true intentions. Key features include enhanced worming capabilities and a new infrastructure for command-and-control (C2).
XCSSET v40 introduces new operational modules, including a Chrome hijacking backdoor and a Telegram trojanizer, significantly escalating its ability to compromise user data and maintain persistence. Researchers recommend defensive measures like AI-driven behavioral analysis and real-time monitoring to detect and counteract these threats.