We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Trojan:MacOS/Xcsset!rfn
Aliases: No associated aliases
Summary
Trojan:MacOS/Xcsset!rfn, a variant of XCSSET, is a modular malware that infects software developers by compromising Xcode projects (.xcodeproj files). The trojan activates and attempts to steal sensitive data, which may include web browser data (cookies, saved passwords, digital wallet extensions), data from communication-related applications such as Telegram, and the contents of the corresponding Notes app when the developer builds the Xcode project.
This variant, first documented by Microsoft Threat Intelligence in March 2025, demonstrates significant evolution from earlier versions with enhanced obfuscation, improved error handling, and multiple persistence mechanisms. Trojan:MacOS/Xcsset!rfn infection presents a significant supply chain risk, as compromised Xcode projects allows it to evolve as more threat actors collaborate to its updates and continued development.
The “!rfn” suffix in this variant denotes that it uses scripting languages and attempts to run payloads directly in memory whenever possible, leaving minimal traces on disk. Detecting such activity often relies on behavioral analysis rather than static file hashes.
- Deactivate Wi-Fi and unplug Ethernet cables to prevent the malware from communicating with its command-and-control (C2) servers or exfiltrating more data.
- If critical files were encrypted or corrupted, restore them from a clean, pre-infection Time Machine snapshot.
- After ensuring the mac is clean, change passwords for macos accounts.
- Examine your Xcode projects for malicious build phases or rules. Compare with known clean versions if possible.
Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts.
You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.