meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

When macOS gets frostbite. [Research Saturday]

CyberWire Daily

N2K Networks, Inc.

Daily News, Tech News, News, Technology

4.61K Ratings

🗓️ 6 December 2025

⏱️ 24 minutes

🧾️ Download transcript

Summary

Jaron Bradley, Director of Jamf Threat Labs, is sharing their work on "ChillyHell: A Deep Dive into a Modular macOS Backdoor." Jamf Threat Labs uncovers a newly notarized macOS backdoor called ChillyHell, tied to past UNC4487 activity and disguised as a legitimate applet. The malware showcases robust host profiling, multiple persistence mechanisms, timestomping, and flexible C2 communications over both DNS and HTTP. Its modular design includes reverse shells, payload delivery, self-updates, and a brute-force component targeting user credentials. The research can be found here: ⁠ChillyHell: A Deep Dive into a Modular macOS Backdoor Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the Cyberwire Network, powered by N2K.

0:09.7

Most environments trust far more than they should, and attackers know it.

0:16.3

Threat Locker solves that by enforcing default deny at the point of execution.

0:25.6

With Threat Locker Allow listing, you stop unknown executables cold. With ring fencing, you control how trusted applications behave.

0:29.6

And with Threat Locker DAC, defense against configurations, you get real assurance that your environment is free of misconfigurations, and clear visibility into whether you meet compliance standards.

0:41.3

Threat Locker is the simplest way to enforce zero-trust principles without the operational pain.

0:46.3

It's powerful protection that gives CISO's real visibility, real control, and real peace of mind.

0:52.3

Threat Locker makes zero-trust attainable, even for small security teams.

0:58.0

See why thousands of organizations choose Threat Locker to minimize alert fatigue,

1:02.4

stop ransomware at the source, and regain control over their environments.

1:07.1

Schedule your demo at Threatlocker.com slash N2K today.

1:11.6

Hello, everyone, and welcome to the CyberWires Research Saturday.

1:28.2

I'm Dave Bittner, and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities,

1:36.1

solving some of the hard problems and protecting ourselves in our rapidly evolving cyberspace.

1:41.9

Thanks for joining us.

1:53.7

So we have some different live hunt rules set up, and this one actually stumbled about because of a way in which it was performing shellouts to collect process information.

2:00.0

And we sort of said, hey, like, there's a lot going on with this executable than just collecting

2:05.8

processes, right?

2:06.8

It's doing some really interesting stuff.

2:09.2

That's Jaron Bradley, director of Jamp Threat Labs.

2:12.2

The research we're discussing today is titled, Chili Hell, a deep dive into a modular macOS backdoor.

2:23.3

So that's kind of what initially caught our attention, and then the more we looked at it and kind of observed it, we saw it aligned with a report that had been previously done by Mandy.

...

Transcript will be available on the free plan in 15 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.