Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

ChillyHell malware continues targeting Mac users with advanced evasion tactics

Advanced evasion tactics keep the 2021 malware active despite Apple revoking developer certificates.

byEmre Çıtak
September 11, 2025
in Cybersecurity

A new report from Jamf Threat Labs reveals that ChillyHell malware remains active against macOS systems. First discovered in 2021 and privately reported by cybersecurity firm Mandiant in 2023, this persistent threat shows no signs of stopping. Jamf researchers found a fresh sample on VirusTotal in May 2024, confirming the malware’s continued operation.

How ChillyHell steals Mac user data

ChillyHell targets sensitive information on infected Mac computers, specifically focusing on usernames and passwords. The malware uses sophisticated methods to avoid detection by security software and researchers.

Advanced evasion techniques make detection difficult

The malware employs two key tactics to stay hidden:

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

  • Timestomping – alters file creation and modification dates to hide malicious activity
  • Dynamic command-and-control protocol switching – changes communication methods to avoid network monitoring

These evasion techniques allow ChillyHell to operate undetected for extended periods, making tracking and removal challenging for security teams.

Developer certificate revocation limits future distribution

Jamf’s investigation found that Apple has revoked the developer certificates linked to ChillyHell. This revocation prevents new versions from being easily distributed but does not remove existing infections from compromised systems.

Mac users should maintain updated security software and exercise caution when downloading applications from untrusted sources. The ChillyHell campaign demonstrates that macOS remains a target for sophisticated malware operations.


Featured image credit

Tags: ChillyHell malware

Related Posts

Free and effective anti-robocall tools are now available

Free and effective anti-robocall tools are now available

October 3, 2025
WestJet cyberattack: 1.2m passengers’ data stolen

WestJet cyberattack: 1.2m passengers’ data stolen

October 2, 2025
Wiz: AI vibe coding leads to insecure authentication

Wiz: AI vibe coding leads to insecure authentication

September 29, 2025
DHS uses AI to detect AI-generated child abuse material

DHS uses AI to detect AI-generated child abuse material

September 29, 2025
Salesforce Agentforce hit by Noma “ForcedLeak” exploit

Salesforce Agentforce hit by Noma “ForcedLeak” exploit

September 26, 2025
Co-op Group reports £75m loss after April cyber-attack

Co-op Group reports £75m loss after April cyber-attack

September 25, 2025

LATEST NEWS

ChatGPT reportedly reduces reliance on Reddit as a data source

Perplexity makes Comet AI browser free, launches background assistant and Chess.com partnership

Light-powered chip makes AI computation 100 times more efficient

Free and effective anti-robocall tools are now available

Choosing the right Web3 server: OVHcloud options for startups to enterprises

Z.AI GLM-4.6 boosts context window to 200K tokens

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy.