BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

CHILLYHELL, ZynorRAT Malware Target Windows, Mac, and Linux Systems

New Malware CHILLYHELL and ZynorRAT Target macOS, Windows, and Linux Systems with Advanced Persistence and Espionage Capabilities

  • Researchers have found two new Malware threats targeting macOS, Windows, and Linux systems.
  • The modular backdoor named CHILLYHELL is developed for Apple macOS and attributed to a group active since 2022.
  • ZynorRAT, a Go-based remote access trojan, can control infected Windows and Linux computers via Telegram.
  • Both malware types focus on persistence, information stealing, and remote control functions.
  • Apple has revoked the developer certificates related to CHILLYHELL after its recent discovery.

Cybersecurity teams have identified two new types of malware targeting multiple operating systems. One, called CHILLYHELL, is a modular backdoor designed for Apple macOS devices and linked to Hacking activity dating back to October 2022. The second, ZynorRAT, is a remote access trojan written in Go, impacting both Windows and Linux computers.

- Advertisement -

According to analysis from Jamf Threat Labs, CHILLYHELL is developed for Intel-based Macs and was found in a sample uploaded to the VirusTotal platform on May 2, 2025. The file, originally notarized by Apple in 2021, was publicly available on Dropbox until Apple revoked the certificates after the discovery.

CHILLYHELL profiles the infected system, establishes persistence in several ways, and communicates with command servers using either HTTP or DNS. The malware can install itself as either a LaunchAgent or LaunchDaemon—a method used to maintain ongoing access to macOS devices. If it cannot modify files directly, the malware changes the user’s shell profile to include launching commands. The researchers, Ferdous Saljooki and Maggie Zirnhelt, noted the malware’s use of “timestomping,” where it alters the creation dates of files to avoid detection. “Between its multiple persistence mechanisms, ability to communicate over different protocols and modular structure, ChillyHell is extraordinarily flexible,” Jamf said.

The malware also has the ability to open a remote shell, download new versions, carry out brute-force password attacks, and collect user account data. “Capabilities such as timestomping and password cracking make this sample an unusual find in the current macOS threat landscape,” the researchers said. More details can be found in Jamf’s official blog post.

Investigators have linked CHILLYHELL to an uncategorized threat group known as UNC4487. According to Google Mandiant, this group has targeted Ukraine government websites for espionage efforts, using malware to trick users into executing malicious files.

- Advertisement -

The second threat, ZynorRAT, relies on a Telegram bot to manage infected devices and was first submitted to VirusTotal on July 8, 2025. Both the Linux and Windows versions allow attackers to collect files, list processes, take screenshots, and execute system commands. While the Windows version mirrors the Linux one, it still depends on Linux-style persistence, suggesting ongoing development.

A report by Sysdig stated, “Its main purpose is to serve as a collection, exfiltration, and remote access tool, which is centrally managed through a Telegram bot.” The malware appears to be the creation of a lone developer, possibly from Turkey, based on Telegram chat language.

Research shows ZynorRAT’s distribution involves the Dosya.co file-sharing service, with evidence that its creator tested the malware on their own computers. The continued creation of tools like ZynorRAT highlights the ongoing advances in malware development.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Tether backs Drift’s $150M hack recovery, eyes Solana

Tether is supporting a recovery plan for the hacked Solana exchange Drift Protocol, which...

Record Bitcoin Miner Selloff in Tightening Q1 2026 Market

Public Bitcoin miners like MARA and CleanSpark sold over 32,000 BTC in Q1 2026,...

Tether funds Drift hack victims in swap for USDT adoption

Tether will donate $127.5 million to help Solana-based exchange Drift Protocol recover $286 million...

Russia-linked crypto exchange Grinex shuts down after $13M hack

The sanctioned Russia-linked crypto exchange Grinex has halted operations after a major hack resulted...

Hayes: U.S.-Iran Conflict May Tank Bitcoin Before Liquidity Surge

Arthur Hayes described markets as being in a 'no trade zone' due to geopolitical...

Must Read

9 DePIN Programs For Passive Income

Here’s something most people don’t realize: your smartphone and PC can generate passive income with almost no effort.I’m not talking about clicking ads for...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading