Skip to main content
Skip to main content
32 entries found. Displaying page 1 of 2.
Updated on Aug 28, 2021

Trojan:MacOS/Xcsset.B, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/Xcsset.B infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

Alert level: severe
Updated on May 20, 2025

Trojan:MacOS/Xcsset.AX, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project. 

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/Xcsseet.AX infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

Alert level: severe
Updated on Jul 03, 2021

Trojan:MacOS/Xcsset!rfn, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/Xcsset!rfn infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

The “!rfn” suffix in this variant denotes that it uses scripting languages and attempts to run payloads directly in memory whenever possible, leaving minimal traces on disk. Detecting such activity often relies on behavioral analysis rather than static file hashes. 

Alert level: severe
Updated on Mar 16, 2022

Trojan:MacOS/Xcsset.A!xp, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/XCSSET.A!xp infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

Alert level: severe
Updated on Jun 22, 2022

Trojan:MacOS/Xcsset.C!MTB, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/Xcsset.C!MTB infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

The “!MTB” suffix refers to Microsoft Threat Behavior, which indicates that this trojan was detected using behavioral analysis or machine learning models. Instead of relying solely on a static signature (like a known file hash), the antivirus engine identified the program's actions, sequence of operations, or code patterns as malicious. These patterns are consistent with the known behavior of the XCSSET family. 

Alert level: severe
Updated on Aug 28, 2022

Trojan:MacOS/Xcsset.B!MTB, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan: MacOS/XCSSET infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

The “!MTB” suffix refers to Microsoft Threat Behavior, which indicates that this trojan was detected using behavioral analysis or machine learning models. Instead of relying solely on a static signature (like a known file hash), the antivirus engine identified the program's actions, sequence of operations, or code patterns as malicious. These patterns are consistent with the known behavior of the XCSSET family. 

Alert level: severe
Updated on May 17, 2022

Trojan:MacOS/XCSSET, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan: MacOS/XCSSET infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development.

Alert level: severe
Updated on Sep 30, 2021

Trojan:MacOS/XCSSET.J, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/XCSSET.J infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

Alert level: severe
Updated on Mar 11, 2022

Trojan:MacOS/XCSSET.A, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/XCSSET.A infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

Alert level: severe
Updated on May 20, 2025

Trojan:MacOS/XCSSET.P, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/XCSSET.P infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

Alert level: severe
Updated on Apr 18, 2025

Trojan:MacOS/XCSSET.SB, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/XCSSET.SB infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

Alert level: severe
Updated on May 20, 2025

Trojan:MacOS/XCSSET.AB, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/XCSSET.AB infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

Alert level: severe
Updated on May 20, 2025

Trojan:MacOS/XCSSET.AZ, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/XCSSET.AZ infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

Alert level: severe
Updated on May 20, 2025

Trojan:MacOS/XCSSET.AW, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/XCSSET.AW infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

Alert level: severe
Updated on May 20, 2025

Trojan:MacOS/XCSSET.AU, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/XCSSET.AU infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

Alert level: severe
Updated on May 20, 2025

Trojan:MacOS/XCSSET.AT, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/XCSSET.AT infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

Alert level: severe
Updated on May 20, 2025

Trojan:MacOS/XCSSET.AV, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/XCSSET.AV infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

Alert level: severe
Updated on May 20, 2025

Trojan:MacOS/XCSSET.AY, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/XCSSET:AY infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

Alert level: severe
Updated on May 20, 2025

Trojan:MacOS/XCSSET.SG, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/XCSSET:SG infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

Alert level: severe
Updated on May 20, 2025

Trojan:MacOS/XCSSET.SE, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.  

This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/XCSSET.SE infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development. 

Alert level: severe