BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

CHILLYHELL, ZynorRAT Malware Target Windows, Mac, and Linux Systems

New Malware CHILLYHELL and ZynorRAT Target macOS, Windows, and Linux Systems with Advanced Persistence and Espionage Capabilities

  • Researchers have found two new Malware threats targeting macOS, Windows, and Linux systems.
  • The modular backdoor named CHILLYHELL is developed for Apple macOS and attributed to a group active since 2022.
  • ZynorRAT, a Go-based remote access trojan, can control infected Windows and Linux computers via Telegram.
  • Both malware types focus on persistence, information stealing, and remote control functions.
  • Apple has revoked the developer certificates related to CHILLYHELL after its recent discovery.

Cybersecurity teams have identified two new types of malware targeting multiple operating systems. One, called CHILLYHELL, is a modular backdoor designed for Apple macOS devices and linked to Hacking activity dating back to October 2022. The second, ZynorRAT, is a remote access trojan written in Go, impacting both Windows and Linux computers.

- Advertisement -

According to analysis from Jamf Threat Labs, CHILLYHELL is developed for Intel-based Macs and was found in a sample uploaded to the VirusTotal platform on May 2, 2025. The file, originally notarized by Apple in 2021, was publicly available on Dropbox until Apple revoked the certificates after the discovery.

CHILLYHELL profiles the infected system, establishes persistence in several ways, and communicates with command servers using either HTTP or DNS. The malware can install itself as either a LaunchAgent or LaunchDaemon—a method used to maintain ongoing access to macOS devices. If it cannot modify files directly, the malware changes the user’s shell profile to include launching commands. The researchers, Ferdous Saljooki and Maggie Zirnhelt, noted the malware’s use of “timestomping,” where it alters the creation dates of files to avoid detection. “Between its multiple persistence mechanisms, ability to communicate over different protocols and modular structure, ChillyHell is extraordinarily flexible,” Jamf said.

The malware also has the ability to open a remote shell, download new versions, carry out brute-force password attacks, and collect user account data. “Capabilities such as timestomping and password cracking make this sample an unusual find in the current macOS threat landscape,” the researchers said. More details can be found in Jamf’s official blog post.

Investigators have linked CHILLYHELL to an uncategorized threat group known as UNC4487. According to Google Mandiant, this group has targeted Ukraine government websites for espionage efforts, using malware to trick users into executing malicious files.

- Advertisement -

The second threat, ZynorRAT, relies on a Telegram bot to manage infected devices and was first submitted to VirusTotal on July 8, 2025. Both the Linux and Windows versions allow attackers to collect files, list processes, take screenshots, and execute system commands. While the Windows version mirrors the Linux one, it still depends on Linux-style persistence, suggesting ongoing development.

A report by Sysdig stated, “Its main purpose is to serve as a collection, exfiltration, and remote access tool, which is centrally managed through a Telegram bot.” The malware appears to be the creation of a lone developer, possibly from Turkey, based on Telegram chat language.

Research shows ZynorRAT’s distribution involves the Dosya.co file-sharing service, with evidence that its creator tested the malware on their own computers. The continued creation of tools like ZynorRAT highlights the ongoing advances in malware development.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Nears $64K Despite Iran Tensions, Trader Caution

Bitcoin regained the $64,000 level despite renewed geopolitical tensions involving the US, Iran, and...

Micron’s AI HBM Boom: $435 to $1,750 Price Target Split

Wall Street's 2026 price targets for Micron stock show extreme divergence, ranging from around...

AI Chatbots May Reinforce Delusions in Vulnerable Users

Researchers propose a new "amplification spiral" framework to explain how AI chatbots could reinforce...

Bitcoin Plunges 50%, Sparking Fears of Imminent Market Collapse

Bitcoin's price has fallen to half its October 2025 peak, sparking fears of a...

Dash Eyes Philippines for Crypto Payments Expansion

Dash is exploring the Philippines as a target market for its low-cost crypto payment...

Must Read

Best Metaverse Tokens to Buy on Binance for 10X Gains

Ever since Facebook renamed their company to Meta, as well as their plans to build a metaverse where we can travel into using Virtual...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading