{"id":41893,"date":"2021-07-22T00:00:00","date_gmt":"2021-07-22T00:00:00","guid":{"rendered":"https:\/\/www.trendmicro.com\/en_us\/research\/21\/g\/updated-xcsset-malware-targets-telegram--other-apps.html"},"modified":"2021-07-22T00:00:00","modified_gmt":"2021-07-22T00:00:00","slug":"updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\/","title":{"rendered":"Updated XCSSET Malware Targets Telegram, Other Apps Threats Analyst Threats Analyst"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/xcsset-update\/xcsset-july2021-main.jpg\"><!-- Begin mPulse library --><!-- END mPulse library --> <head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width\"> <meta name=\"description\" content=\"In our last update on the XCSSET campaign, we updated some of its features targeting latest macOS 11 (Big Sur). Since then, the campaign added more features to its toolset, which we have continually monitored. We have also discovered the mechanism used to steal information from various apps, a behavior that has been present since we first discussed XCSSET.\"> <meta name=\"robots\" content=\"index,follow\"> <meta name=\"keywords\" content=\"latest news,malware,mobile,articles, news, reports\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge,chrome=1\"> <meta name=\"template\" content=\"article1withouthero\"> <meta property=\"article:published_time\" content=\"2021-07-22\"> <meta property=\"article:tag\" content=\"malware\"> <meta property=\"article:section\" content=\"latest news\"> <link rel=\"icon\" type=\"image\/ico\" href=\"\/content\/dam\/trendmicro\/favicon.ico\"> <link rel=\"canonical\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/g\/updated-xcsset-malware-targets-telegram--other-apps.html\"> <title>Updated XCSSET Malware Targets Telegram, Other Apps<\/title> <link href=\"https:\/\/fonts.googleapis.com\/css?family=Open+Sans:300,300i,400,400i,600\" rel=\"stylesheet\">\n<link href=\"\/\/customer.cludo.com\/css\/296\/1798\/cludo-search.min.css\" type=\"text\/css\" rel=\"stylesheet\"> <link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch.min.css\" type=\"text\/css\"> <meta property=\"og:url\" content=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/g\/updated-xcsset-malware-targets-telegram--other-apps.html\"><br \/>\n<meta property=\"og:title\" content=\"Updated XCSSET Malware Targets Telegram, Other Apps\"><br \/>\n<meta property=\"og:description\" content=\"In our last update on the XCSSET campaign, we updated some of its features targeting latest macOS 11 (Big Sur). Since then, the campaign added more features to its toolset, which we have continually monitored. We have also discovered the mechanism used to steal information from various apps, a behavior that has been present since we first discussed XCSSET.\"><br \/>\n<meta property=\"og:site_name\" content=\"Trend Micro\"><br \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/xcsset-update\/xcsset-july2021-main.jpg\"><br \/>\n<meta property=\"og:locale\" content=\"en_US\"> <meta name=\"twitter:card\" content=\"summary_large_image\"><br \/>\n<meta name=\"twitter:site\" content=\"@TrendMicro\"><br \/>\n<meta name=\"twitter:title\" content=\"Updated XCSSET Malware Targets Telegram, Other Apps\"><br \/>\n<meta name=\"twitter:description\" content=\"In our last update on the XCSSET campaign, we updated some of its features targeting latest macOS 11 (Big Sur). Since then, the campaign added more features to its toolset, which we have continually monitored. We have also discovered the mechanism used to steal information from various apps, a behavior that has been present since we first discussed XCSSET.\"><br \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/xcsset-update\/xcsset-july2021-main.jpg\"> <\/head> <body class=\"articlepage page basicpage context-business\" id=\"readabilityBody\" readability=\"51.290747897249\"> <!-- Page Scroll: Back to Top --> <a id=\"page-scroll\" title=\"VerticalPageScroll\" href=\"javascript:jumpScroll($(this).scrollTop());\"> <span class=\"icon-chevron-up\"><\/span> <\/a> <!-- \/* Data Layer *\/ --> <\/p>\n<div class=\"root responsivegrid\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12 \">\n<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"888959628\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\" readability=\"11.5\">\n<div class=\"article-details\" role=\"heading\" readability=\"43\"> <span class=\"article-details__bar\" role=\"img\"><\/span> <\/p>\n<p class=\"article-details__display-tag\">Malware<\/p>\n<p class=\"article-details__description\">In our last update on the XCSSET campaign, we updated some of its features targeting latest macOS 11 (Big Sur). Since then, the campaign added more features to its toolset, which we have continually monitored. We have also discovered the mechanism used to steal information from various apps, a behavior that has been present since we first discussed XCSSET.<\/p>\n<p class=\"article-details__author-by\">By: Mickey Jin, Steven Du <time class=\"article-details__date\">July 22, 2021<\/time> <span>Read time:&nbsp;<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words) <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<hr class=\"research-layout-divider\"> <main class=\"main--content col-xs-12 col-md-8 col-md-push-2\"> <\/p>\n<div class=\"richText\" readability=\"42.761772853186\">\n<div readability=\"30.828254847645\">\n<p>In our last <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/d\/xcsset-quickly-adapts-to-macos-11-and-m1-based-macs.html\">update<\/a> on the XCSSET campaign, we updated some of its features targeting latest macOS 11 (Big Sur). Since then, the campaign added more features to its toolset, which we have continually monitored. We have also discovered the mechanism used to steal information from various apps, a behavior that has been present since we first discussed XCSSET.<\/p>\n<p><b>How XCSSET Malware Steals Information<\/b><\/p>\n<p>From the first version of XCSSET, we noticed that it collects some data from various apps and sends these back to its command-and-control (C&amp;C) server. However, we did not know how the threat actor would use the data. We recently found the mechanism used to steal the data, and learned that it contains valuable and sensitive information that can be used for various purposes.<\/p>\n<p>Take the malicious AppleScript file \u201ctelegram.applescript\u201d as an example. As the name implies, Telegram is the target app in this case. Its main logic is compressing the folder \u201c~\/Library\/Group Containers\/6N38VWS5BX.ru.keepcoder.Telegram\u201d into a .ZIP file, and uploading the said file to a C&amp;C server.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/xcsset-update\/xcsset-01.png\" alt=\"Figure 1. Code of telegram.applescript\"><figcaption>Figure 1. Code of telegram.applescript<\/figcaption><\/figure>\n<\/p><\/div>\n<div>\n<div class=\"richText\" readability=\"44\">\n<div readability=\"33\">\n<p>To find the purpose of collecting the folder, we performed a simple test using two Mac machines:<\/p>\n<ol>\n<li>Install Telegram on both machine A and B.\/li&gt;<\/li>\n<li>On machine A, log in with a valid Telegram account. Do nothing using Telegram on machine B.\/li&gt;<\/li>\n<li>Copy \u201c~\/Library\/Group Containers\/6N38VWS5BX.ru.keepcoder.Telegram\u201d folder from machine A to machine B, and replace the existing folder.<\/li>\n<li>Run Telegram on machine B. When this is done, it is already logged in with the same account used on machine A.<\/li>\n<\/ol>\n<p>On macOS, the Application sandbox directory <i>~\/Library\/Containers\/com.xxx.xxx<\/i> and <i>~\/Library\/Group Containers\/com.xxx.xxx<\/i> can be accessed (with READ\/WRITE permissions) by common users. This differs from the practice on iOS. Not all executable files are sandboxed on macOS, which means a simple script can steal all the data stored in the sandbox directory. We recommend that application developers refrain from storing sensitive data in the sandbox directory, particularly those related to login information.&nbsp;<\/p>\n<p><b>Sensitive data targeted by XCSSET<\/b><\/p>\n<p>XCSSET malware has stolen lots of critical privacy data of these applications, with most of them these stored in their sandbox directories. Here, we\u2019ll show how it is done in Chrome.<\/p>\n<p>In Chrome, the stolen data includes any passwords stored by the user to dump the data, XCSSET needs to get the <i>safe_storage_key<\/i> using the command <i>security find- generic-password -wa \u2018Chrome\u2019<\/i> . However, this command requires root privileges. To get around this requirement, the malware puts all the operations that need root privilege together in a single function, as seen in Figure 2:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/xcsset-update\/xcsset-02.png\" alt=\"Figure 2. Operations requiring administrator privilege\"><figcaption>Figure 2. Operations requiring administrator privilege<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>The user is then prompted to grant these privileges via a fake dialog box.<\/p>\n<p>Once it has obtained the Chrome safe_storage_key, it decrypts all the sensitive data and uploads it to the C&amp;C server.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/xcsset-update\/xcsset-03.png\" alt=\"Figure 3. Information stealing code targeting Google Chrome\"><figcaption>Figure 3. Information stealing code targeting Google Chrome<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/xcsset-update\/xcsset-04.png\" alt=\"Figure 4. Information stealing code targeting Google Chrome\"><figcaption>Figure 4. Information stealing code targeting Google Chrome<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"38.5\">\n<div readability=\"22\">\n<p>Similar scripts can be found targeting the following applications:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Contacts<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Evernote<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Notes<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Opera<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Skype<\/span><\/li>\n<li><span class=\"rte-red-bullet\">WeChat<\/span><\/li>\n<\/ul>\n<p><b>New C&amp;C Domains<\/b><\/p>\n<p>From April 20 to 22, 2021, some new domain names appeared, all of them resolve to the IP address 94.130.27.189, which XCSSET also used before.<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">atecasec.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">linebrand.xyz<\/span><\/li>\n<li><span class=\"rte-red-bullet\">mantrucks.xyz<\/span><\/li>\n<li><span class=\"rte-red-bullet\">monotal.xyz<\/span><\/li>\n<li><span class=\"rte-red-bullet\">nodeline.xyz<\/span><\/li>\n<li><span class=\"rte-red-bullet\">sidelink.xyz<\/span><\/li>\n<\/ul>\n<p>Similarly, the domain name below now resolves from a non-malicious IP address to 94.130.27.189.<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">icloudserv.com<\/span><\/li>\n<\/ul>\n<p>All these new domain names have an HTTPS certificate from \u201cLet\u2019s Encrypt,\u201d which is valid from April 22 to July 21, 2021.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/xcsset-update\/xcsset-05.png\" alt=\"Figure 5. HTTPS certificate for C&amp;C servers\"><figcaption>Figure 5. HTTPS certificate for C&amp;C servers<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"43\">\n<div readability=\"31\">\n<p>From April 22, 2021, onwards, all C&amp;C domain names resolved to 194.87.186.66. On May 1, a new domain name (irc-nbg.v001.com) was resolved to the original C&amp;C IP address 94.130.27.189. This new domain name suggests an IRC server is now located at the said IP address, which does not appear to be currently related to XCSSET.<\/p>\n<p>From June 9 to 10, 2021, all existing domain names related to XCSSET C&amp;C servers were removed, Instead, the following new domain names were added:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">atecasec.info<\/span><\/li>\n<li><span class=\"rte-red-bullet\">datasomatic.ru<\/span><\/li>\n<li><span class=\"rte-red-bullet\">icloudserv.ru<\/span><\/li>\n<li><span class=\"rte-red-bullet\">lucidapps.info<\/span><\/li>\n<li><span class=\"rte-red-bullet\">relativedata.ru<\/span><\/li>\n<li><span class=\"rte-red-bullet\">revokecert.ru<\/span><\/li>\n<li><span class=\"rte-red-bullet\">safariperks.ru<\/span><\/li>\n<\/ul>\n<p>However, on June 24, these servers were taken offline by the attackers. Currently, we have been unable to locate the new servers of XCSSET.<\/p>\n<p><b>Other Behavior Changes<\/b><\/p>\n<p><i>Bootstrap.applescript<\/i><\/p>\n<p>In bootstrap.applescript, the first noteworthy change is the use of the latest C&amp;C domains:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/xcsset-update\/xcsset-06.png\" alt=\"Figure 6. C&amp;C domains used\"><figcaption>Figure 6. C&amp;C domains used<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>Note that aside from the available domain names, the IP address is also part of the list. Even if all the domains get suddenly shut down in the future, the C&amp;C server still can be reached via IP address.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/xcsset-update\/xcsset-07.png\" alt=\"Figure 7. Modules in use\"><figcaption>Figure 7. Modules in use<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>A new module, \u201ccanary,\u201d is added to perform XSS injection on the Chrome Canary browser from Google, which is an experimental version of the Chrome browser.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/xcsset-update\/xcsset-08.png\" alt=\"Figure 8. Modules in use, showing removed module\"><figcaption>Figure 8. Modules in use, showing removed module<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"36\">\n<div readability=\"17\">\n<p>Compared to the last version, the calling for \u201cscreen_sim\u201d is removed.<\/p>\n<p><i>Replicator.applescript<\/i><\/p>\n<p>As the first step of infecting local Xcode projects, from the last version, they changed the injected build phrase or build rule\u2019s ID from a hardcoded ID to a randomly generated ID; however, the last six characters of the ID is still hardcoded as \u201cAAC43A\u201d. In the latest version, the hardcoded postfix changed to \u201c6D902C\u201d.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/xcsset-update\/xcsset-09.png\" alt=\"Figure 9. Changed postfix\"><figcaption>Figure 9. Changed postfix<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"34\">\n<div readability=\"13\">\n<p>Regarding the logic of the script in injecting fake build phase and build rule: Previously, it called a malicious Mach-O file located in a hidden folder in the infected Xcode project. Now, it calls the curl command to download a shell script named \u201ca\u201d from the C&amp;C server and passes its contents to \u201csh\u201d to execute it. This way, any new infected Xcode projects from the latest version will not contain additional malicious files.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/xcsset-update\/xcsset-10.png\" alt=\"Figure 10. Code for downloading and running the shellcode\"><figcaption>Figure 10. Code for downloading and running the shellcode<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<p>Here are the contents of the shell script file downloaded from the C&amp;C server. It downloads the landing Mach-O component Pods from the C&amp;C server, saves it as \/tmp\/exec.$$, adds an executable flag, and executes it.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/xcsset-update\/xcsset-11.png\" alt=\"Figure 11. Downloaded code\"><figcaption>Figure 11. Downloaded code<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<p>Same as before, the Mach-O file, \u201cPods,\u201d is generated by the SHC tool. The primary logic of the shell script extracted from it is quite similar to the one used before. The following screenshots list some of the notable changes.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/xcsset-update\/xcsset-12.png\" alt=\"Figure 12. The working folder changed from \u201cGemeKit\u201d to \u201cGeoServices\u201d\"><figcaption>Figure 12. The working folder changed from \u201cGemeKit\u201d to \u201cGeoServices\u201d<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/xcsset-update\/xcsset-13.png\" alt=\"Figure 13. The fake app\u2019s name changed from Xcode.app to Mail.app\"><figcaption>Figure 13. The fake app\u2019s name changed from Xcode.app to Mail.app<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/xcsset-update\/xcsset-14.png\" alt=\"Figure 14. Temp files are created for debugging\"><figcaption>Figure 14. Temp files are created for debugging<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"36.805190538765\">\n<div class=\"responsive-table-wrap\" readability=\"21.031537450723\">\n<p><b>Defending against XCSSET<\/b><\/p>\n<p>The changes we\u2019ve encountered in XCSSET do not reflect a fundamental change in its behavior but do constitute refinements in its tactics. The discovery of how it can steal information from various apps highlights the degree to which the malware aggressively attempts to steal various kinds of information from affected systems.<\/p>\n<p>To protect systems from this type of threat, users should only download apps from official and legitimate marketplaces. Users can also consider multilayered security solutions such as&nbsp;<a href=\"https:\/\/www.trendmicro.com\/en_us\/forHome\/products\/antivirus-for-mac.html\">Trend Micro Maximum Security<\/a>, which provides comprehensive security and multidevice protection against cyberthreats.<\/p>\n<p>Enterprises can take advantage of Trend Micro\u2019s&nbsp;<a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/user-protection\/sps.html\">Smart Protection Suites<\/a>&nbsp;with XGen\u2122 security, which infuses high-fidelity&nbsp;<a href=\"https:\/\/www.trendmicro.com\/vinfo\/tmr\/?\/us\/security\/definition\/machine-learning\">machine learning<\/a>&nbsp;into a blend of threat protection techniques to eliminate security gaps across any user activity or endpoint.<\/p>\n<p><b>Indicators of Compromise<\/b><\/p>\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody readability=\"5\">\n<tr readability=\"3\">\n<td valign=\"top\">\n<p>File Name<\/p>\n<\/td>\n<td valign=\"top\">\n<p>SHA256<\/p>\n<\/td>\n<td valign=\"top\" readability=\"5\">\n<p>Trend Micro Detection Name<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td valign=\"top\">\n<p>bootstrap.applescript<\/p>\n<\/td>\n<td valign=\"top\" readability=\"5\">\n<p>f453e8ae426133ace544cd4bb1ab2435620a8d4d5f70b936d8f3118e22f254e8<\/p>\n<\/td>\n<td valign=\"top\">\n<p>Trojan.macOS.XCSSET.C<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td valign=\"top\">\n<p>replicator.applescript<\/p>\n<\/td>\n<td valign=\"top\" readability=\"5\">\n<p>7a51fd3080ee5f65c9127603683718a3fd4f3e0b13de6141824908a6d3d4b558<\/p>\n<\/td>\n<td valign=\"top\">\n<p>Trojan.macOS.XCSSET.C<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td valign=\"top\">\n<p>Pods<\/p>\n<\/td>\n<td valign=\"top\" readability=\"5\">\n<p>bbcc8a101ae0e7fc546dab235387b0bf7461e097578fedcb25c4195bc973f895<\/p>\n<\/td>\n<td valign=\"top\">\n<p>Trojan.macOS.XCSSET.C<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td valign=\"top\">\n<p>a<\/p>\n<\/td>\n<td valign=\"top\" readability=\"5\">\n<p>d8f14247ef18edaaae2c20dee975cd98a914b47548105cfbd30febefe2fa2a6b<\/p>\n<\/td>\n<td valign=\"top\">\n<p>Trojan.macOS.XCSSET.C<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><i>C&amp;C Servers<\/i><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">194.87.186.66<\/span><\/li>\n<li><span class=\"rte-red-bullet\">atecasec.info<\/span><\/li>\n<li><span class=\"rte-red-bullet\">datasomatic.ru<\/span><\/li>\n<li><span class=\"rte-red-bullet\">icloudserv.ru<\/span><\/li>\n<li><span class=\"rte-red-bullet\">lucidapps.info<\/span><\/li>\n<li><span class=\"rte-red-bullet\">relativedata.ru<\/span><\/li>\n<li><span class=\"rte-red-bullet\">revokecert.ru<\/span><\/li>\n<li><span class=\"rte-red-bullet\">safariperks.ru<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<section class=\"tag--list\">\n<p>Tags<\/p>\n<\/section>\n<p> <\/main> <\/article>\n<\/div>\n<\/div><\/div>\n<\/div>\n<p> <!-- \/* Core functionality javascripts, absolute URL to leverage Akamai CDN *\/ --> <!--For Modal-start--> <\/p>\n<p> <span>sXpIBdPeKzI9PC2p0SWMpUSM2NSxWzPyXTMLlbXmYa0R20xk<\/span> <\/p>\n<p> <!--For Modal-end--> <!-- Go to www.addthis.com\/dashboard to customize your tools --> <\/body> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/g\/updated-xcsset-malware-targets-telegram--other-apps.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In our last update on the XCSSET campaign, we updated some of its features targeting latest macOS 11 (Big Sur). Since then, the campaign added more features to its toolset, which we have continually monitored. We have also discovered the mechanism used to steal information from various apps, a behavior that has been present since we first discussed XCSSET. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":41894,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9461,9465,28,163],"class_list":["post-41893","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-articles-news-reports","tag-latest-news","tag-malware","tag-mobile"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Updated XCSSET Malware Targets Telegram, Other Apps Threats Analyst Threats Analyst 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Updated XCSSET Malware Targets Telegram, Other Apps Threats Analyst Threats Analyst 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-07-22T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1547\" \/>\n\t<meta property=\"og:image:height\" content=\"605\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Updated XCSSET Malware Targets Telegram, Other Apps Threats Analyst Threats Analyst\",\"datePublished\":\"2021-07-22T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\\\/\"},\"wordCount\":1447,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst.png\",\"keywords\":[\"Articles, News, Reports\",\"Latest News\",\"Malware\",\"Mobile\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\\\/\",\"name\":\"Updated XCSSET Malware Targets Telegram, Other Apps Threats Analyst Threats Analyst 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst.png\",\"datePublished\":\"2021-07-22T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst.png\",\"width\":1547,\"height\":605},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Updated XCSSET Malware Targets Telegram, Other Apps Threats Analyst Threats Analyst\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Updated XCSSET Malware Targets Telegram, Other Apps Threats Analyst Threats Analyst 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\/","og_locale":"en_US","og_type":"article","og_title":"Updated XCSSET Malware Targets Telegram, Other Apps Threats Analyst Threats Analyst 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-07-22T00:00:00+00:00","og_image":[{"width":1547,"height":605,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Updated XCSSET Malware Targets Telegram, Other Apps Threats Analyst Threats Analyst","datePublished":"2021-07-22T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\/"},"wordCount":1447,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst.png","keywords":["Articles, News, Reports","Latest News","Malware","Mobile"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\/","url":"https:\/\/www.threatshub.org\/blog\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\/","name":"Updated XCSSET Malware Targets Telegram, Other Apps Threats Analyst Threats Analyst 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst.png","datePublished":"2021-07-22T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst.png","width":1547,"height":605},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/updated-xcsset-malware-targets-telegram-other-apps-threats-analyst-threats-analyst\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Updated XCSSET Malware Targets Telegram, Other Apps Threats Analyst Threats Analyst"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41893","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=41893"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41893\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/41894"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=41893"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=41893"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=41893"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}