ChillyHell is a modular macOS backdoor targeting Intel-based Macs. Public reporting links it to UNC4487, a cluster assessed by Mandiant as a suspected espionage actor that has used compromised Ukrainian websites to socially engineer victims into executing malware. Evidence indicates ChillyHell has been active since at least 2021 and remained largely undetected for years despite being developer-signed and passing Apple notarization.
After execution, ChillyHell profiles the infected host, establishes persistence through multiple macOS mechanisms, and initiates command-and-control communications over HTTP or DNS. Reported persistence methods include LaunchAgent installation, LaunchDaemon installation, and shell profile modification so the malware can run at login, system startup, or when a new shell session is opened. Its modular architecture supports remote command execution, reverse shell access, downloading updated versions of itself, and fetching additional payloads.
ChillyHell also employs defense-evasion techniques designed to reduce user suspicion and hinder detection. Reported behaviors include timestomping of created artifacts and opening a benign decoy web page in the default browser. Some reporting also attributes password-cracking and user-account enumeration functionality to the malware, indicating support for brute-force activity and follow-on intrusion operations.
ChillyHell has been associated with targeted operations rather than broad commodity distribution. Apple has revoked developer certificates associated with known samples, but the malware is notable as an example of signed and notarized malicious code on macOS.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A dormant macOS threat is showing signs of new life, according to a report from cybersecurity firm Jamf. The company has been closely monitoring a macOS backdoor named ChillyHell, which has been active since 2021.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Il exploite des mécanismes avancés de persistance tels que « LaunchAgents et LaunchDaemons » intégrés au système d'exploitation ... Les attaquants créent des fichiers de configuration « .plist » pointant vers leur binaire malveillant. Ainsi, à chaque démarrage de l’ordinateur ou connexion d’utilisateur, le malware est relancé automatiquement
Il exploite des mécanismes avancés de persistance tels que « LaunchAgents et LaunchDaemons » intégrés au système d'exploitation ... Les attaquants créent des fichiers de configuration « .plist » pointant vers leur binaire malveillant. Ainsi, à chaque démarrage de l’ordinateur ou connexion d’utilisateur, le malware est relancé automatiquement
Once executed, the malware extensively profiles the compromised host and establishes persistence using three different methods, following which it initializes command-and-control (C2) communication with a hard-coded server ... over HTTP or DNS
CHILLYHELL supports a wide range of commands that allow it to launch a reverse shell to the C2 IP address
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Modular macOS backdoor written in C++ for Intel architectures (per excerpt).
A modular backdoor targeting macOS, providing attackers with persistent access and modular capabilities.
A modular backdoor targeting macOS systems, providing persistent unauthorized access and modular functionality for attackers.
A modular macOS backdoor that can bypass security checks, remain hidden, establish persistence via LaunchAgent, LaunchDaemon, and shell profile injection, provide remote command-line access, drop additional payloads, and crack user passwords. It also used timestomping, altered C2 communications, opened a decoy Google.com page to reduce suspicion, and was able to pass Apple notarization.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.