
About this episode
Jaron Bradley, Director of Jamf Threat Labs, is sharing their work on "ChillyHell: A Deep Dive into a Modular macOS Backdoor." Jamf Threat Labs uncovers a newly notarized macOS backdoor called ChillyHell, tied to past UNC4487 activity and disguised as a legitimate applet.
The malware showcases robust host profiling, multiple persistence mechanisms, timestomping, and flexible C2 communications over both DNS and HTTP. Its modular design includes reverse shells, payload delivery, self-updates, and a brute-force component targeting user credentials.
The research can be found here:
ChillyHell: A Deep Dive into a Modular macOS Backdoor
Get every episode summarized
Each time CyberWire Daily publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from CyberWire Daily

Clear your calendar, it’s Patch Tuesday.
CyberWire Daily
Sep 9, 202630:40completed

Worming its way through WeChat.
CyberWire Daily
Sep 8, 202630:03completed

This call may be monitored. [Special Edition]
CyberWire Daily
Sep 7, 202638:33pending

When hackers control the clock. [T-Minus: Space-Cyber Briefing]
CyberWire Daily
Sep 6, 202623:43pending