Apple slips up on ChillyHell macOS malware, lets it past security . . . for 4 years
ID: 72ab905c-efc6-5d15-9da6-e82c17156256
STIX ID: report--72ab905c-efc6-5d15-9da6-e82c17156256
Feed Name: The Register (Security)
Threat Score
ChillyHell is a notarized, modular macOS backdoor (Intel C++) that researchers found publicly hosted since 2021 and likely active for years; it uses multiple persistence methods (LaunchAgent/LaunchDaemon and shell profile modification), timestomping evasion, interchangeable C2 protocols, and modules for downloading payloads, credential brute-forcing, and data collection, and has been linked to prior reporting attributing a variant to UNC4487.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
