logo

Apple slips up on ChillyHell macOS malware, lets it past security . . . for 4 years

ID: 72ab905c-efc6-5d15-9da6-e82c17156256

STIX ID: report--72ab905c-efc6-5d15-9da6-e82c17156256

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2025-09-10

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

ChillyHell is a notarized, modular macOS backdoor (Intel C++) that researchers found publicly hosted since 2021 and likely active for years; it uses multiple persistence methods (LaunchAgent/LaunchDaemon and shell profile modification), timestomping evasion, interchangeable C2 protocols, and modules for downloading payloads, credential brute-forcing, and data collection, and has been linked to prior reporting attributing a variant to UNC4487.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.