White Paper
Deconstructing a Zero-Day: XCSSET Malware
XCSSET is one of the most persistent and sophisticated malware families targeting macOS, designed to compromise user privacy and gain access to sensitive information. Researchers have observed continuous efforts by its developers to enhance its capabilities and exploit new vulnerabilities. A notable example involved the exploitation of a macOS Transparency, Consent, and Control (TCC) framework vulnerability, identified as CVE-2021-30713. TCC is responsible for managing application permissions to sensitive resources such as microphones, cameras, and other protected data. By bypassing this framework, attackers could potentially gain unauthorized access to private information without user consent. The XCSSET malware demonstrates how cybercriminals continually adapt their techniques to evade s
