BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

CHILLYHELL, ZynorRAT Malware Target Windows, Mac, and Linux Systems

New Malware CHILLYHELL and ZynorRAT Target macOS, Windows, and Linux Systems with Advanced Persistence and Espionage Capabilities

  • Researchers have found two new Malware threats targeting macOS, Windows, and Linux systems.
  • The modular backdoor named CHILLYHELL is developed for Apple macOS and attributed to a group active since 2022.
  • ZynorRAT, a Go-based remote access trojan, can control infected Windows and Linux computers via Telegram.
  • Both malware types focus on persistence, information stealing, and remote control functions.
  • Apple has revoked the developer certificates related to CHILLYHELL after its recent discovery.

Cybersecurity teams have identified two new types of malware targeting multiple operating systems. One, called CHILLYHELL, is a modular backdoor designed for Apple macOS devices and linked to Hacking activity dating back to October 2022. The second, ZynorRAT, is a remote access trojan written in Go, impacting both Windows and Linux computers.

- Advertisement -

According to analysis from Jamf Threat Labs, CHILLYHELL is developed for Intel-based Macs and was found in a sample uploaded to the VirusTotal platform on May 2, 2025. The file, originally notarized by Apple in 2021, was publicly available on Dropbox until Apple revoked the certificates after the discovery.

CHILLYHELL profiles the infected system, establishes persistence in several ways, and communicates with command servers using either HTTP or DNS. The malware can install itself as either a LaunchAgent or LaunchDaemon—a method used to maintain ongoing access to macOS devices. If it cannot modify files directly, the malware changes the user’s shell profile to include launching commands. The researchers, Ferdous Saljooki and Maggie Zirnhelt, noted the malware’s use of “timestomping,” where it alters the creation dates of files to avoid detection. “Between its multiple persistence mechanisms, ability to communicate over different protocols and modular structure, ChillyHell is extraordinarily flexible,” Jamf said.

The malware also has the ability to open a remote shell, download new versions, carry out brute-force password attacks, and collect user account data. “Capabilities such as timestomping and password cracking make this sample an unusual find in the current macOS threat landscape,” the researchers said. More details can be found in Jamf’s official blog post.

Investigators have linked CHILLYHELL to an uncategorized threat group known as UNC4487. According to Google Mandiant, this group has targeted Ukraine government websites for espionage efforts, using malware to trick users into executing malicious files.

- Advertisement -

The second threat, ZynorRAT, relies on a Telegram bot to manage infected devices and was first submitted to VirusTotal on July 8, 2025. Both the Linux and Windows versions allow attackers to collect files, list processes, take screenshots, and execute system commands. While the Windows version mirrors the Linux one, it still depends on Linux-style persistence, suggesting ongoing development.

A report by Sysdig stated, “Its main purpose is to serve as a collection, exfiltration, and remote access tool, which is centrally managed through a Telegram bot.” The malware appears to be the creation of a lone developer, possibly from Turkey, based on Telegram chat language.

Research shows ZynorRAT’s distribution involves the Dosya.co file-sharing service, with evidence that its creator tested the malware on their own computers. The continued creation of tools like ZynorRAT highlights the ongoing advances in malware development.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

GitLab Flaw Actively Exploited After Disclosure

A critical GitLab vulnerability (CVE-2026-19478, CVSS 9.4) enables unauthenticated attackers to modify or delete...

PEPE Surges 25% Weekly, Outperforms Bitcoin and Ethereum

PEPE surged 14.2% in 24 hours and over 25% in the past week, outperforming...

Tom Lee: Avoid Robinhood Stock in 2026

Tom Lee of Fundstrat named Robinhood Markets Inc stock as one to avoid in...

MANTRA Token Plunges 18.5% as Chain Halts After Incident

MANTRA's native token plunged 18.5% to an all-time low of $0.004126 before the chain...

CME, Kalshi clash at CFTC roundtable over prediction market rules

CME Group Chairman Terry Duffy and Kalshi co-founder Luana Lopes Lara clashed during a...

Must Read

7 Best Cryptocurrency Lending Platforms in 2025 (Ranked & Reviewed)

QUICK LINKSOur MethodologyHow to Choose the Best Crypto Lending Platform: Key Factors to ConsiderIn-Depth Reviews of the 7 Best Crypto Lending Platforms1. Nexo -...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading