216.73.217.22

Learn about ChillyHell, a modular Mac backdoor

· Published 10/09/2025 16:18 · Modified 10/09/2025 20:12

Export JSON

Essential information

Published
10/09/2025 16:18
Modified
10/09/2025 20:12
Tags
2025-09-10 backdoor c2 chillyhell dns http macos matanbuchus modular notarized password-cracking persistence
Related entities
1 intrusion sets (apt), 13 techniques (mitre), 2 others

Description

is a sophisticated discovered in 2021 that has evaded detection by antivirus vendors. It is a C++ malware targeting Intel architectures, using multiple mechanisms and communication protocols. The performs host profiling, establishes through LaunchAgents, LaunchDaemons, or shell profile injection, and communicates with command and control servers via or . 's structure allows for various capabilities, including reverse shell access, self-updating, payload execution, and local password cracking. The malware's flexibility, stealth techniques, and notarization status make it a significant threat in the landscape.

External references