#ChillyHell
深度解析CHILLYHELL macOS后门与ZynorRAT远程访问木马:多平台威胁下的安全挑战

https://qian.cx/posts/18011AFF-122F-40E7-844C-208185B4C040
December 28, 2025 at 12:52 PM
When macOS gets frostbite. [Research Saturday]

Jaron Bradley, Director of Jamf Threat Labs, is sharing their work on "ChillyHell: A Deep Dive into a Modular macOS Backdoor." Jamf Threat Labs uncovers a newly notarized macOS backdoor called ChillyHell, tied to past UNC4487 activit…
#hackernews #news
When macOS gets frostbite. [Research Saturday]
Jaron Bradley, Director of Jamf Threat Labs, is sharing their work on "ChillyHell: A Deep Dive into a Modular macOS Backdoor." Jamf Threat Labs uncovers a newly notarized macOS backdoor called ChillyHell, tied to past UNC4487 activity and disguised as a legitimate applet. The malware showcases robust host profiling, multiple persistence mechanisms, timestomping, and flexible C2 communications over both DNS and HTTP. Its modular design includes reverse shells, payload delivery, self-updates, and a brute-force component targeting user credentials. The research can be found here: ⁠ChillyHell: A Deep Dive into a Modular macOS Backdoor
thecyberwire.com
December 7, 2025 at 4:31 PM
ChillyHell

also known as HEUR:Trojan-Dropper.OSX.Agent.u Type: Hybrid Threat Platform: Mac OS 9 Last updated: 09/30/25 11:22 pm Threat Level: Medium Description ChillyHell is malicious software that infects macOS by disguising itself as a legitimate program. Once installed, it can download more…
ChillyHell
also known as HEUR:Trojan-Dropper.OSX.Agent.u Type: Hybrid Threat Platform: Mac OS 9 Last updated: 09/30/25 11:22 pm Threat Level: Medium Description ChillyHell is malicious software that infects macOS by disguising itself as a legitimate program. Once installed, it can download more malware and open a backdoor, allowing attackers to remotely control the computer, steal information, and more. ChillyHell Threat Removal MacScan can detect and remove ChillyHell Hybrid Threat from your system, as well as provide protection against other security and privacy threats. A 30-day trial is available to scan your system for this threat. Download MacScan The post ChillyHell appeared first on SecureMac.
www.securemac.com
September 30, 2025 at 11:44 PM
このmacOSマルウェアは何年も休眠していたが、ひそかに数千台のデバイスに感染していた可能性がある

(画像提供:Shutterstock) (画像提供:Shutterstock) ChillyHellは2021年に作成されたモジュール型のmacOSバックドアで、Appleの公証を通過し、何年も検出されなかった Mandiantが2023年に発見したが、情報は公開されず、ウイルス対策ツールも対応しなかった Jamfが2025年に公表し、現在も公証が有効でウイルス対策エンジンで検出されていないことを明らかにした…
このmacOSマルウェアは何年も休眠していたが、ひそかに数千台のデバイスに感染していた可能性がある
(画像提供:Shutterstock) (画像提供:Shutterstock) ChillyHellは2021年に作成されたモジュール型のmacOSバックドアで、Appleの公証を通過し、何年も検出されなかった Mandiantが2023年に発見したが、情報は公開されず、ウイルス対策ツールも対応しなかった Jamfが2025年に公表し、現在も公証が有効でウイルス対策エンジンで検出されていないことを明らかにした 少なくとも4年間、モジュール型のApple向けマルウェアが、ウイルス対策ソリューションに検出されることなく、標的デバイスに展開されていた。 さらに悪いことに、少なくとも2年間は(一部の)サイバーセキュリティコミュニティがその存在を認識していた。 今週初め、セキュリティ研究者のJamfが新しいレポートを公開し、ChillyHellについて詳述した。これは、リバースシェルの提供、自身のアップデート、追加ペイロードの取得と実行が可能なモジュール型バックドアである。 2023年に初検出 バックドア自体は特別なものではないが、長期間検出されなかったことが注目に値する。どうやらこのマルウェアは2021年に作成され、Appleに提出された。その際、公証チェックを通過し、Appleの自動システムは悪意のあるものと判断しなかった。 チェックを通過できた理由は、ペイロードが複数のモジュールに分割されていたこと、有効なApple Developer IDで署名されていたこと、無害なアプリとして設計されていたことが挙げられる。さらに、権限昇格やネットワークスキャンなど、標準的な不審な挙動もなかった。 2023年までは主要なプラットフォームでウイルス対策による検出がなく、見過ごされていた。しかし2023年、Mandiant(Googleのサイバーセキュリティ部門)が脅威インテリジェンスブリーフィングでこれを特定し、ウクライナ当局者を自動車保険サイト経由で標的にしていたUNC4487という脅威アクターに帰属させた。 しかしこのブリーフィングは非公開で技術的な詳細もなく共有されたため、広範なセキュリティコミュニティはその存在を把握できなかった。Appleも公証を取り消さず、ウイルス対策ツールも依然として検出しなかった。 そして2025年、Jamf Threat Labsがこのマルウェアを公に公開し、「ChillyHell」と命名、アーキテクチャや永続性、回避技術について詳述した。さらに、この時点でもAppleの公証は有効なままであり、VirusTotalにアップロードされた一部サンプルは依然としてウイルス対策で検出されていないことを強調した。 出典: The Register 翻訳元:
blackhatnews.tokyo
September 29, 2025 at 7:46 PM
Jamf Threat Labs Uncovers New Activity of Mac Malware ‘ChillyHell’ #ChillyHellmalware #JamfThreatLabsreport #MacMalware
Jamf Threat Labs Uncovers New Activity of Mac Malware ‘ChillyHell’
  Jamf Threat Labs has published a new report highlighting the resurgence of Mac malware known as ChillyHell. Initially detected in 2021 and later privately disclosed by cybersecurity company Mandiant in 2023, the malware resurfaced this past May when Jamf identified a fresh sample on VirusTotal—a platform used for analyzing suspicious files and URLs. Once a Mac is compromised, ChillyHell can steal sensitive data such as usernames and passwords. What sets this malware apart is its ability to use timestomping—altering file timestamps—and its capability to switch C2 protocols to bypass detection. According to Jamf, “the developer certificates associated with ChillyHell have been revoked.” While this action restricts its ongoing development, it doesn’t mean the malware has completely disappeared from circulation. How Mac Users Can Stay Protected from Malware To minimize the risk of infection, avoid downloading applications from unverified sources such as GitHub or third-party websites. The Mac App Store remains the safest place to install apps, as Apple rigorously vets software before publishing. Alternatively, purchase apps directly from trusted developers via their official websites. Using cracked or pirated software dramatically increases the risk of malware exposure. Users should also avoid clicking links in unsolicited emails or messages. If a message appears legitimate, verify the sender’s email and check the link carefully. On a Mac, you can Control-click a link, choose Copy Link Address, and paste it into a text editor to preview the real URL before visiting. For additional security, Macworld offers resources such as a guide on whether antivirus software is necessary, a detailed list of Mac viruses and trojans, and a comparison of the best Mac security software available. Apple also provides built-in protections in macOS and releases regular security updates. Installing these updates promptly is essential, as Apple reissues corrected patches if any flaws are found.
dlvr.it
September 21, 2025 at 2:25 PM
ChillyHell Unleashed: How This Mac Malware Sneaks Past Security and Takes Over Your Device

ChillyHell malware resurfaces, bypasses macOS security, and sneaks into your Mac like a ninja! Discover its tricks and how to stay safe from this sneaky threat.
thenimblenerd.com?p=1055210
ChillyHell Unleashed: How This Mac Malware Sneaks Past Security and Takes Over Your Device
ChillyHell, the macOS threat, is back and stealthier than ever. This malware bypasses security checks, disguises itself with clever tactics, and even opens a decoy Google page to avoid suspicion. It's like the James Bond of cyber threats, but instead of saving the world, it's here to control your Mac.
thenimblenerd.com
September 18, 2025 at 12:14 PM
ChillyHell Unleashed: How Dormant macOS Malware Outsmarted Apple for Years

ChillyHell malware flies under the radar on macOS, evading detection with notarization. Discover its sneaky tactics, persistence, and modular design in this wild ride!
thenimblenerd.com?p=1055104
ChillyHell Unleashed: How Dormant macOS Malware Outsmarted Apple for Years
ChillyHell, a modular macOS backdoor, has been sneaking around undetected for years, slipping past Apple's notarization process like a ninja in a fruit aisle. Despite being flagged in 2023, it remained notarized and active. Researchers note its flexibility and stealth, reminding us: not all malicious code wears a villain's cape.
thenimblenerd.com
September 18, 2025 at 10:46 AM
Sikkerhetsforskere gir en oppdatering på «Chillyhell».
Mac-skadevare har ligget skjult i flere år – kan knekke passordene dine
Sikkerhetsforskere gir en oppdatering på «Chillyhell».
www.digi.no
September 17, 2025 at 8:23 PM
ChillyHell modular macOS malware OKed by Apple in 2021
www.theregister.com/2025/09/10/c...
ChillyHell modular macOS malware OKed by Apple in 2021
: 'We do believe that this was likely the creation of a cybercrime group,' threat hunter tells The Reg
www.theregister.com
September 15, 2025 at 12:01 PM
September 15, 2025 at 5:39 AM
ChillyHell modular macOS malware OKed by Apple in 2021 www.theregister.com/2025/09/10/c...
ChillyHell modular macOS malware OKed by Apple in 2021
: 'We do believe that this was likely the creation of a cybercrime group,' threat hunter tells The Reg
www.theregister.com
September 13, 2025 at 3:12 AM
New modular macOS malware dubbed ChillyHell evades detection and adapts to targets, marking a rare and advanced threat to Apple systems.
#macOS #Malware #ChillyHell #CyberSecurity #Apple #APT #ThreatIntel www.theregister.com/2025/09/10/c...
ChillyHell modular macOS malware OKed by Apple in 2021
: 'We do believe that this was likely the creation of a cybercrime group,' threat hunter tells The Reg
www.theregister.com
September 12, 2025 at 11:58 AM
ChillyHell macOS Malware Resurfaces, Using Google.com as a Decoy

A previously dormant macOS threat, ChillyHell, is reviving. Read how this malware can bypass security checks, remain hidden,…

#hackernews #news
ChillyHell macOS Malware Resurfaces, Using Google.com as a Decoy
A previously dormant macOS threat, ChillyHell, is reviving. Read how this malware can bypass security checks, remain hidden,…
hackread.com
September 12, 2025 at 10:53 AM
https://www.matricedigitale.it/2025/09/11/apple-rafforza-macos-memory-integrity-enforcement-ferma-chillyhell/
Apple rafforza macOS: Memory Integrity Enforcement ferma ChillyHell - Matrice Digitale
Apple introduce Memory Integrity Enforcement su macOS e iOS, combinando EMTE, PAC e allocatori tipizzati per neutralizzare backdoor come ChillyHell.
www.quellochenoncidicono.site
September 12, 2025 at 4:50 AM
📌 ChillyHell macOS Malware Resurfaces with Advanced Evasion Techniques https://www.cyberhub.blog/article/13043-chillyhell-macos-malware-resurfaces-with-advanced-evasion-techniques
ChillyHell macOS Malware Resurfaces with Advanced Evasion Techniques
The ChillyHell malware, also identified as MATANBUCHUS, has re-emerged as a significant threat to macOS systems. This backdoor malware leverages Google.com as a decoy to circumvent security checks and maintain stealth on compromised systems. By exploiting trusted domains, ChillyHell effectively bypasses network-based detection mechanisms, allowing attackers to establish persistent remote access. A critical aspect of ChillyHell's evasion strategy is its utilization of stolen code-signing certificates. These certificates, typically employed to validate software authenticity and integrity, enable the malware to masquerade as legitimate applications. This tactic undermines traditional security measures that rely on code signing verification, complicating detection efforts. The resurgence of ChillyHell underscores the shifting threat landscape for macOS environments. While macOS has historically been perceived as a more secure platform, the increasing sophistication of macOS-targeted malware challenges this notion. Cybersecurity professionals must adapt their defensive strategies to address these advanced evasion techniques. To counter the threats posed by ChillyHell, organizations should deploy advanced detection methodologies, including behavioral analysis and anomaly detection. Implementing regular audits of code-signing certificates can aid in identifying and revoking compromised certificates. Furthermore, user education on the risks associated with downloading software from untrusted sources is paramount, as malicious actors often exploit stolen certificates to distribute malware disguised as legitimate applications. The re-emergence of ChillyHell has substantial implications for the cybersecurity landscape. It emphasizes the necessity for comprehensive security measures across all platforms, including macOS. Cybersecurity experts must remain abreast of emerging threats and continuously refine their defensive strategies to mitigate risks posed by sophisticated malware such as ChillyHell.
www.cyberhub.blog
September 12, 2025 at 12:40 AM
Apple slips up on ChillyHell macOS malware, lets it past security . . . for 4 years

'We do believe that this was likely the creation of a cybercrime group,' threat hunter tells The Reg
ChillyHell, a modular macOS backdoor believed to be long dormant, has likely been infe…

#apple #hackernews #news
Apple slips up on ChillyHell macOS malware, lets it past security . . . for 4 years
'We do believe that this was likely the creation of a cybercrime group,' threat hunter tells The Reg ChillyHell, a modular macOS backdoor believed to be long dormant, has likely been infecting computers for years while flying under the radar, according to security researchers who spotted a malware sample uploaded to VirusTotal in May.…
go.theregister.com
September 11, 2025 at 10:57 PM
Apple、macOSマルウェア「ChillyHell」を見逃し、セキュリティを4年間も回避

Apple slips up on ChillyHell macOS malware, lets it past security . . . for 4 years #Register (Sep 10)

www.theregister.com/2025/09/10/c...
ChillyHell modular macOS malware OKed by Apple in 2021
: 'We do believe that this was likely the creation of a cybercrime group,' threat hunter tells The Reg
www.theregister.com
September 11, 2025 at 10:01 PM
Apple introduce Memory Integrity Enforcement su macOS e iOS, combinando EMTE, PAC e allocatori tipizzati per neutralizzare backdoor come ChillyHell.

#ChillyHell #iPhone #JamfThreatLabs #macOS #MemoryIntegrityEnforcement
www.matricedigitale.it/2025/09/11/a...
September 11, 2025 at 8:25 PM
Apple slips up on ChillyHell macOS malware, lets it past security . . . for 4 years
ChillyHell modular macOS malware OKed by Apple in 2021
: 'We do believe that this was likely the creation of a cybercrime group,' threat hunter tells The Reg
buff.ly
September 11, 2025 at 8:16 PM
September 11, 2025 at 7:14 PM