Researchers reported that an updated XCSSET malware strain expanded its data-theft capabilities on macOS, using malicious AppleScript files to collect and compress sensitive data from multiple applications before exfiltrating it to attacker-controlled infrastructure. The malware was found targeting Telegram session data stored in application sandbox and group container directories, creating a path for account takeover on another Mac, while also harvesting information from Contacts, Evernote, Notes, Opera, Skype, and WeChat.
The updated malware also targeted Google Chrome by displaying a fake privilege prompt to obtain the browser’s safe_storage_key, which it then used to decrypt and upload stored passwords and other sensitive data. Researchers said the operators rotated multiple command-and-control domains and IP addresses and modified the malware’s Xcode project infection chain so newer variants downloaded payloads remotely instead of embedding additional malicious files locally.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
On June 24, 2021, the attackers took the newer XCSSET servers offline. The malware's direct IP fallback in bootstrap.applescript would have helped preserve reachability even if domains were shut down.
From June 9 to June 10, 2021, previously used XCSSET C2 domains were removed and replaced with atecasec.info, datasomatic.ru, icloudserv.ru, lucidapps.info, relativedata.ru, revokecert.ru, and safariperks.ru. The malware's bootstrap component was updated to use the latest domains and a direct IP fallback.
On May 1, 2021, the domain irc-nbg.v001.com resolved to the original C2 IP address 94.130.27.189. The report noted it appeared to host an IRC server that did not seem related to XCSSET at the time.
From April 22, 2021 onward, all observed XCSSET command-and-control domain names resolved to 194.87.186.66. This marked a change in the malware's C2 infrastructure.
Between April 20 and April 22, 2021, researchers observed new XCSSET-related domains including atecasec.com, linebrand.xyz, mantrucks.xyz, monotal.xyz, nodeline.xyz, and sidelink.xyz resolving to 94.130.27.189. These domains used Let's Encrypt certificates valid from April 22 to July 21, 2021.
Trend Micro documented updated XCSSET malware features, including theft of Telegram session data, Chrome passwords, and data from Contacts, Evernote, Notes, Opera, Skype, and WeChat. The report also described new infection logic that downloads payloads remotely and a new canary module targeting Google Chrome Canary.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.