#ChillyHell
Jamf researchers have detailed a Mac backdoor called ChillyHell that passed Apple’s notarization checks in 2021 and went unnoticed until very recently.
'ChillyHell' backdoor hid in notarized Mac apps for four years
Jamf researchers have detailed a Mac backdoor called ChillyHell that passed Apple's notarization checks in 2021 and went unnoticed until very recently.
appleinsider.com
September 10, 2025 at 12:17 PM
Jamf researchers have published a technical analysis of ChillyHell, a macOS backdoor that's been silently distributed in the wild since 2021

www.jamf.com/blog/chillyh...
Learn about ChillyHell, a modular Mac backdoor
Discover its origin, how it compromises macOS and more importantly, how the JTL detected this malicious threat to keep Jamf customers safe.
www.jamf.com
September 11, 2025 at 11:42 AM
Dormant macOS Backdoor ChillyHell Resurfaces
Dormant macOS Backdoor ChillyHell Resurfaces
With multiple persistence mechanisms, the modular malware can brute-force passwords, drop payloads, and communicate over different protocols.
www.darkreading.com
September 10, 2025 at 3:59 PM
CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux Systems

Cybersecurity researchers have discovered two new malware families, including a modular Apple macOS backdoor called CHILLYHELL and a Go-based remote access trojan (RAT) named ZynorRAT th…

#apple #hackernews #news
CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux Systems
Cybersecurity researchers have discovered two new malware families, including a modular Apple macOS backdoor called CHILLYHELL and a Go-based remote access trojan (RAT) named ZynorRAT that can target both Windows and Linux systems. According to an analysis from Jamf Threat Labs, ChillyHell is written in C++ and is developed for Intel architectures. CHILLYHELL is the name assigned to a malware
thehackernews.com
September 11, 2025 at 12:57 PM
ChillyHell macOS Malware Profiles Compromised Machines and Maintain Persistence with 3 Methods
ChillyHell macOS Malware Profiles Compromised Machines and Maintain Persistence with 3 Methods
cybersecuritynews.com
September 11, 2025 at 1:20 PM
September 11, 2025 at 7:14 PM
New malware threats CHILLYHELL and ZynorRAT target macOS, Windows, and Linux systems. Stay vigilant and update your security measures. #CyberSecurity #MalwareAlert #CHILLYHELL #ZynorRAT Link: thedailytechfeed.com/emerging-thr...
September 10, 2025 at 4:13 PM
Apple slips up on ChillyHell macOS malware, lets it past security . . . for 4 years
ChillyHell modular macOS malware OKed by Apple in 2021
: 'We do believe that this was likely the creation of a cybercrime group,' threat hunter tells The Reg
www.theregister.com
September 10, 2025 at 7:14 PM
Mac malware's been living rent-free for months while Apple's "security" takes a coffee break. Gatekeeper's about as useful as a chocolate teapot—again.
ChillyHell malware continues to go undetected on macOS, according to Jamf
New malware incorporates technology to make it more difficult to detect.
www.macworld.com
September 10, 2025 at 10:30 PM
深度解析CHILLYHELL macOS后门与ZynorRAT远程访问木马:多平台威胁下的安全挑战

https://qian.cx/posts/18011AFF-122F-40E7-844C-208185B4C040
December 28, 2025 at 12:52 PM
ChillyHell' backdoor hid in notarized Mac apps for four years
appleinsider.com
September 11, 2025 at 2:51 PM
Sikkerhetsforskere gir en oppdatering på «Chillyhell».
Mac-skadevare har ligget skjult i flere år – kan knekke passordene dine
Sikkerhetsforskere gir en oppdatering på «Chillyhell».
www.digi.no
September 17, 2025 at 8:23 PM
September 15, 2025 at 5:39 AM
Jamf Threat Labs Uncovers New Activity of Mac Malware ‘ChillyHell’ #ChillyHellmalware #JamfThreatLabsreport #MacMalware
Jamf Threat Labs Uncovers New Activity of Mac Malware ‘ChillyHell’
  Jamf Threat Labs has published a new report highlighting the resurgence of Mac malware known as ChillyHell. Initially detected in 2021 and later privately disclosed by cybersecurity company Mandiant in 2023, the malware resurfaced this past May when Jamf identified a fresh sample on VirusTotal—a platform used for analyzing suspicious files and URLs. Once a Mac is compromised, ChillyHell can steal sensitive data such as usernames and passwords. What sets this malware apart is its ability to use timestomping—altering file timestamps—and its capability to switch C2 protocols to bypass detection. According to Jamf, “the developer certificates associated with ChillyHell have been revoked.” While this action restricts its ongoing development, it doesn’t mean the malware has completely disappeared from circulation. How Mac Users Can Stay Protected from Malware To minimize the risk of infection, avoid downloading applications from unverified sources such as GitHub or third-party websites. The Mac App Store remains the safest place to install apps, as Apple rigorously vets software before publishing. Alternatively, purchase apps directly from trusted developers via their official websites. Using cracked or pirated software dramatically increases the risk of malware exposure. Users should also avoid clicking links in unsolicited emails or messages. If a message appears legitimate, verify the sender’s email and check the link carefully. On a Mac, you can Control-click a link, choose Copy Link Address, and paste it into a text editor to preview the real URL before visiting. For additional security, Macworld offers resources such as a guide on whether antivirus software is necessary, a detailed list of Mac viruses and trojans, and a comparison of the best Mac security software available. Apple also provides built-in protections in macOS and releases regular security updates. Installing these updates promptly is essential, as Apple reissues corrected patches if any flaws are found.
dlvr.it
September 21, 2025 at 2:25 PM
Malware infectou Macs durante 4 anos sem ser descoberto pela Apple
Desenvolvido em 2021, o malware ChillyHell pode ter infectado Macs sem ser detectado ao longo de quatro anos, de acordo com pesquisadores da empresa de segurança cibernética Jamf. Uma nova amostra do agente malicioso foi identificada em maio, indicando que ele está ativo e evoluindo. Conforme comunicado divulgado na segunda-feira (8), o malware passou pelo processo de autenticação da Apple como um software aparentemente legítimo em 2021. **Desde então, vinha sendo distribuído como um programa para Macs com processadores Intel** , nos quais pode ter se instalado de maneira oculta. O malware foi distribuído como programa legítimo durante quatro anos. (Imagem: Jamf Threat Labs/Divulgação) ## Como age o ChillyHell? Quando instalado no dispositivo, o malware para Macs utiliza diferentes táticas para permanecer oculto. Uma delas é o “timestomping”, que consiste na alteração das informações sobre data e horário dos arquivos criados, fazendo-os parecer mais antigos, o que dificulta identificar quando a infecção aconteceu. * O agente malicioso também possui vários meios de se manter ativo no computador, como se programar para iniciar todas as vezes que o usuário fizer login; * Outra possibilidade é o disfarce como programa que executa tarefas de manutenção do sistema em segundo plano; * Já para minimizar as suspeitas do usuário, o ChillyHell pode abrir uma página do Google no navegador padrão ao se comunicar com seus servidores de controle; * Ao se conectar a eles, **o malware fornece uma linha de comando para que os invasores controlem o Mac remotamente e realizem ataques para quebrar as senhas do usuário**. A primeira detecção deste vírus para macOS aconteceu em 2023, quando a Mandiant o identificou em um ciberataque realizado pelo grupo UNC4487 contra membros do governo da Ucrânia. Na ocasião, ele ajudou a comprometer um site de seguros de automóveis que era utilizado pelas autoridades. No entanto, a empresa manteve os detalhes em sigilo, deixando a comunidade em geral sem saber da sua existência. Dessa forma, ele continuou agindo em silêncio, sem ser detectado pelas ferramentas de segurança, mas **agora a Apple o sinalizou como malware e revogou os certificados do desenvolvedor associados ao ChillyHell**. Com chips da própria Apple, o MacBook Air não é alvo do malware. (Imagem: Getty Images) ## Macs infectados pelo ChillyHell continuam em risco A aprovação do malware como um programa legítimo pelo sistema de verificação da Apple pode ter sido facilitada pela divisão de suas cargas úteis em módulos, segundo o relatório. Além disso, ele possuía a assinatura de um desenvolvedor e não apresentava comportamentos fora do padrão. Com a sua sinalização pela gigante de Cupertino, a distribuição do ChillyHell para novas vítimas fica comprometida, mas os Macs infectados continuam em risco. Neste caso, **é necessário que o usuário faça a remoção do malware manualmente** , por meio de programas de segurança adequados. Para reduzir os riscos de instalar softwares maliciosos, a Apple recomenda realizar downloads somente de fontes oficiais, como a App Store, sempre verificando a procedência do desenvolvedor. Outra dica é manter o sistema operacional atualizado. Gostou do conteúdo? Continue acompanhando as notícias mais recentes no TecMundo e compartilhe-as nas redes sociais com os amigos.
www.tecmundo.com.br
September 11, 2025 at 8:12 PM
Dormant macOS Backdoor ChillyHell Resurfaces
Dormant macOS Backdoor ChillyHell Resurfaces
www.darkreading.com
September 11, 2025 at 7:13 PM
ChillyHell: A New macOS Backdoor Bypassed Apple Notarization for Years
ChillyHell: A New macOS Backdoor Bypassed Apple Notarization for Years
securityonline.info
September 11, 2025 at 4:05 PM
Deux nouvelles familles de malwares menacent macOS, Windows et Linux : un backdoor modulaire pour macOS nommé CHILLYHELL et un RAT Go, ZynorRAT. CHILLYHELL, codé en C++ pour architectures Intel, a été analysé par #JamfThreatLabs 🛡️💻 #CyberSecurity #IAÉthique #InnovationIA https://shorturl.at/tSyEM
CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux Systems
CHILLYHELL macOS malware, notarized since 2021, exposed May 2025 with flexible persistence and C2 evasion tactics.
thehackernews.com
September 11, 2025 at 4:00 PM
CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux Systems Cybersecurity researchers have discovered two new malware families, including a modular Apple macOS backdoor ca...

Origin | Interest | Match
September 10, 2025 at 2:45 PM
📢 ChillyHell : un backdoor macOS modulaire notarisé, analysé par Jamf
📝 Selon Jamf Threat Labs, ChillyHell est un **backdoor macOS modulaire** sophistiqué, lié initiale…
https://cyberveille.ch/posts/2025-09-10-chillyhell-un-backdoor-macos-modulaire-notarise-analyse-par-jamf/ #ChillyHell #Cyberveille
September 11, 2025 at 4:30 AM
CHILLYHELL : Un backdoor caché sur macOS… validé par Apple !
https://mac4ever.com/191768
September 11, 2025 at 3:00 PM
When macOS gets frostbite. [Research Saturday]

Jaron Bradley, Director of Jamf Threat Labs, is sharing their work on "ChillyHell: A Deep Dive into a Modular macOS Backdoor." Jamf Threat Labs uncovers a newly notarized macOS backdoor called ChillyHell, tied to past UNC4487 activit…
#hackernews #news
When macOS gets frostbite. [Research Saturday]
Jaron Bradley, Director of Jamf Threat Labs, is sharing their work on "ChillyHell: A Deep Dive into a Modular macOS Backdoor." Jamf Threat Labs uncovers a newly notarized macOS backdoor called ChillyHell, tied to past UNC4487 activity and disguised as a legitimate applet. The malware showcases robust host profiling, multiple persistence mechanisms, timestomping, and flexible C2 communications over both DNS and HTTP. Its modular design includes reverse shells, payload delivery, self-updates, and a brute-force component targeting user credentials. The research can be found here: ⁠ChillyHell: A Deep Dive into a Modular macOS Backdoor
thecyberwire.com
December 7, 2025 at 4:31 PM
ChillyHell macOS Malware Resurfaces, Using Google.com as a Decoy

A previously dormant macOS threat, ChillyHell, is reviving. Read how this malware can bypass security checks, remain hidden,…

#hackernews #news
ChillyHell macOS Malware Resurfaces, Using Google.com as a Decoy
A previously dormant macOS threat, ChillyHell, is reviving. Read how this malware can bypass security checks, remain hidden,…
hackread.com
September 12, 2025 at 10:53 AM
Apple slips up on ChillyHell macOS malware, lets it past security . . . for 4 years

'We do believe that this was likely the creation of a cybercrime group,' threat hunter tells The Reg
ChillyHell, a modular macOS backdoor believed to be long dormant, has likely been infe…

#apple #hackernews #news
Apple slips up on ChillyHell macOS malware, lets it past security . . . for 4 years
'We do believe that this was likely the creation of a cybercrime group,' threat hunter tells The Reg ChillyHell, a modular macOS backdoor believed to be long dormant, has likely been infecting computers for years while flying under the radar, according to security researchers who spotted a malware sample uploaded to VirusTotal in May.…
go.theregister.com
September 11, 2025 at 10:57 PM