Related Threat Clusters
-
XCSSET v40 Targets macOS Developers via Poisoned Xcode Projects
XCSSET v40 has emerged as a significant threat to macOS developers, utilizing poisoned Xcode projects to compromise local builds and execute supply chain attacks. This version can hijack Chrome and Trojanize Telegram…
3 articles · Updated August 3, 2026 -
XCSSET Malware Evolves with Enhanced Obfuscation and Persistence Techniques
The XCSSET malware has released a new variant, v40, targeting macOS systems and specifically infecting Xcode projects. This version employs advanced obfuscation techniques, including polymorphic payload generation and…
3 articles · Updated September 9, 2026 -
Chaos Ransomware Deploys msaRAT to Evade Detection via Browsers
The Chaos ransomware group has introduced a new Rust-based remote access trojan (RAT) named msaRAT, which disguises command-and-control (C2) traffic through legitimate web browsers like Chrome and Microsoft Edge. By…
8 articles · Updated July 23, 2026 -
TwinLoot Malware Exploits Microsoft Cloud for Command-and-Control Operations
A new Python-based malware framework named TwinLoot has been discovered, utilizing Microsoft Azure and 365 services for its command-and-control (C2) operations. Researchers from Ontinue Cyber Defense Center identified…
8 articles · Updated August 18, 2026
Recent Intelligence Reports
- Xcsset V40 Malware Analysis — unit42.paloaltonetworks.com · September 9, 2026
- New Malware turns Microsoft cloud into its control center — Csoonline · August 18, 2026
- XCSSET v40 Abuses Chrome DevTools Protocol to Steal Cookies and Run Commands — Cybersecuritynews · August 3, 2026
- Chaos ransomware deploys browser — Securityaffairs.Co · July 23, 2026
- Chaos ransomware uses browser — Feeds.4Sysops · July 23, 2026
- Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process — Feeds2.Feedburner · July 23, 2026