
CyberWire Daily
When macOS gets frostbite. [Research Saturday]
Dec 6, 2025 · 24 min · Season 9 · Episode 404Bonus
0:00-24:40
Streams straight from the publisher. podnod never proxies or re-hosts episode audio.
Jaron Bradley, Director of Jamf Threat Labs, is sharing their work on "ChillyHell: A Deep Dive into a Modular macOS Backdoor." Jamf Threat Labs uncovers a newly notarized macOS backdoor called ChillyHell, tied to past UNC4487 activity and disguised as a legitimate applet.
The malware showcases robust host profiling, multiple persistence mechanisms, timestomping, and flexible C2 communications over both DNS and HTTP. Its modular design includes reverse shells, payload delivery, self-updates, and a brute-force component targeting user credentials.
The research can be found here:
Jaron Bradley,
linkedin.comJamf
linkedin.com
redcanary.com