Episode

When macOS gets frostbite.

Podcast
Research Saturday
Published
Dec 6, 2025
Duration seconds
1480
Processing state
not_requested
Canonical source
https://thecyberwire.com/podcasts/research-saturday/404/notes
Audio
https://pdst.fm/e/pdrl.fm/6ec23a/traffic.megaphone.fm/CYBW9324297938.mp3?updated=1764952171
JSON
/v1/public/podcasts/research-saturday-1377435/episodes/when-macos-gets-frostbite
Markdown
/podcast/research-saturday-1377435/when-macos-gets-frostbite.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/when-macos-gets-frostbite/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/research-saturday-1377435/when-macos-gets-frostbite.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Jaron Bradley, Director of Jamf Threat Labs, is sharing their work on "ChillyHell: A Deep Dive into a Modular macOS Backdoor." Jamf Threat Labs uncovers a newly notarized macOS backdoor called ChillyHell, tied to past UNC4487 activity and disguised as a legitimate applet. The malware showcases robust host profiling, multiple persistence mechanisms, timestomping, and flexible C2 communications over both DNS and HTTP. Its modular design includes reverse shells, payload delivery, self-updates, and a brute-force component targeting user credentials. The research can be found here: ⁠ChillyHell: A Deep Dive into a Modular macOS Backdoor Learn more about your ad choices. Visit megaphone.fm/adchoices