Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

This macOS malware was laying dormant for years, but may have been silently infecting thousands of devices

Tech Wavo by Tech Wavo
September 12, 2025
in Computers
0




  • ChillyHell is a modular macOS backdoor created in 2021 that passed Apple’s notarization and stayed undetected for years
  • Mandiant spotted it in 2023, but the info wasn’t shared publicly, so AV tools didn’t catch on
  • Jamf exposed it in 2025, revealing it’s still notarized and not flagged by antivirus engines

For at least four years, a piece of modular Apple malware was being deployed on target devices, without being flagged by antivirus solutions.

To make matters worse, for at least two years, (a part of) the cybersecurity community was aware of its existence.

Earlier this week, security researchers Jamf published a new report, detailing ChillyHell, a modular backdoor that provides its operators with a reverse shell, the ability to update itself, and an option of fetching and executing additional payloads.


You may like

First detection in 2023

While the backdoor in itself is not out of the ordinary, the fact that it remained undetected for a long time is. Apparently, the malware was created in 2021, when it was submitted to Apple. It passed notarization checks, meaning Apple’s automated systems didn’t flag it as malicious.

It managed to pass the checks because its payloads were split across modules, it was signed with a valid Apple Developer ID, and was designed as a harmless app. Furthermore, it had no standard behavioral red flags such as privilege escalation, or network scanning.

Up until 2023, it operated undetected, with no antivirus detections across major platforms. However, in 2023, Mandiant (Google’s cybersecurity arm) identified it in a threat intelligence briefing, and even attributed it to UNC4487, a threat actor that was seen targeting Ukrainian officials via an auto insurance website.

But the briefing was shared privately and without technical details, leaving the broader security community in the dark about its existence. Apple did not revoke the notarization, and AV tools still didn’t flag it.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Fast forward to 2025, and now Jamf Threat Labs publicly disclosed the malware, gave it the name ChillyHell, and detailed its architecture, persistence, and evasion techniques. It also stressed that even at this point, Apple’s notarization remained valid, and some samples uploaded to VirusTotal are still not being flagged by antivirus.

Via The Register

You might also like

Previous Post

Google Launches Affordable Gemini AI Plus Plan Under $5 A Month

Next Post

Astro Bot Joyful controller pre-orders live: where to buy the new DualSense, key info, and the best links to save right now

Next Post
Astro Bot Joyful controller pre-orders live: where to buy the new DualSense, key info, and the best links to save right now

Astro Bot Joyful controller pre-orders live: where to buy the new DualSense, key info, and the best links to save right now

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Mitigating supply chain vulnerabilities | TechRadar

by Tech Wavo
September 12, 2025
0
Google warns Salesloft attack may have compromised Workspace accounts and Salesforce instances
Computers

The recent arrests of four suspects linked to cyber attacks on major UK retailers like Marks and Spencer, Co-op and...

Read more

NYT Strands hints and answers for Friday, September 12 (game #558)

by Tech Wavo
September 12, 2025
0
NYT Strands hints and answers for Monday, August 11 (game #526)
Computers

Looking for a different day?A new NYT Strands puzzle appears at midnight each day for your time zone – which...

Read more

How DevOps tools are opening the gates for high-profile cyberattacks

by Tech Wavo
September 12, 2025
0
How DevOps tools are opening the gates for high-profile cyberattacks
Computers

Source code is a critical asset for every company, and platforms like GitHub and Atlassian serve as secure vaults for...

Read more

The best gaming keyboards of 2025

by Tech Wavo
September 12, 2025
0
The best gaming keyboards of 2025
Computers

The best gaming keyboards bring a greater feeling of comfort and control to your PC play time, whether you’re sinking...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock