Loading cryptocurrency prices...

CHILLYHELL, ZynorRAT Malware Target Windows, Mac, and Linux Systems

New Malware CHILLYHELL and ZynorRAT Target macOS, Windows, and Linux Systems with Advanced Persistence and Espionage Capabilities

  • Researchers have found two new Malware threats targeting macOS, Windows, and Linux systems.
  • The modular backdoor named CHILLYHELL is developed for Apple macOS and attributed to a group active since 2022.
  • ZynorRAT, a Go-based remote access trojan, can control infected Windows and Linux computers via Telegram.
  • Both malware types focus on persistence, information stealing, and remote control functions.
  • Apple has revoked the developer certificates related to CHILLYHELL after its recent discovery.

Cybersecurity teams have identified two new types of malware targeting multiple operating systems. One, called CHILLYHELL, is a modular backdoor designed for Apple macOS devices and linked to Hacking activity dating back to October 2022. The second, ZynorRAT, is a remote access trojan written in Go, impacting both Windows and Linux computers.

- Advertisement -

According to analysis from Jamf Threat Labs, CHILLYHELL is developed for Intel-based Macs and was found in a sample uploaded to the VirusTotal platform on May 2, 2025. The file, originally notarized by Apple in 2021, was publicly available on Dropbox until Apple revoked the certificates after the discovery.

CHILLYHELL profiles the infected system, establishes persistence in several ways, and communicates with command servers using either HTTP or DNS. The malware can install itself as either a LaunchAgent or LaunchDaemon—a method used to maintain ongoing access to macOS devices. If it cannot modify files directly, the malware changes the user’s shell profile to include launching commands. The researchers, Ferdous Saljooki and Maggie Zirnhelt, noted the malware’s use of “timestomping,” where it alters the creation dates of files to avoid detection. “Between its multiple persistence mechanisms, ability to communicate over different protocols and modular structure, ChillyHell is extraordinarily flexible,” Jamf said.

The malware also has the ability to open a remote shell, download new versions, carry out brute-force password attacks, and collect user account data. “Capabilities such as timestomping and password cracking make this sample an unusual find in the current macOS threat landscape,” the researchers said. More details can be found in Jamf’s official blog post.

Investigators have linked CHILLYHELL to an uncategorized threat group known as UNC4487. According to Google Mandiant, this group has targeted Ukraine government websites for espionage efforts, using malware to trick users into executing malicious files.

- Advertisement -

The second threat, ZynorRAT, relies on a Telegram bot to manage infected devices and was first submitted to VirusTotal on July 8, 2025. Both the Linux and Windows versions allow attackers to collect files, list processes, take screenshots, and execute system commands. While the Windows version mirrors the Linux one, it still depends on Linux-style persistence, suggesting ongoing development.

A report by Sysdig stated, “Its main purpose is to serve as a collection, exfiltration, and remote access tool, which is centrally managed through a Telegram bot.” The malware appears to be the creation of a lone developer, possibly from Turkey, based on Telegram chat language.

Research shows ZynorRAT’s distribution involves the Dosya.co file-sharing service, with evidence that its creator tested the malware on their own computers. The continued creation of tools like ZynorRAT highlights the ongoing advances in malware development.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Bitcoin Risks Deeper Drop as $107K Support Faces Critical Test

Bitcoin’s recovery after Friday’s crash remains weak, with prices hovering just above a key...

Trump Imposes 50% Tariff on India, Cites Russian Oil Imports

Russian oil imports were at the center of trade tensions between India and the...

Bitcoin Struggles to Recover After $19B Liquidation and ETF Slump

Bitcoin is going through a phase of rebuilding market confidence after a major sell-off...

Apple Joins Robotics Race as TSLA Faces Rising Mag-7 Competition

Apple is expanding manufacturing in Vietnam to build tabletop robots and smart home devices. Morgan...

Trump Confirms US-China Trade War, Bitcoin Market Reacts to Tariffs

President Donald Trump has declared that the United States is currently in a trade...
- Advertisement -

Must Read

Top 10 Best Blockchain Games

If you want to know about the best blockchain games then read this article carefully. We listed the best games you can play and...