When macOS gets frostbite. [Research Saturday]
CyberWire Daily6 Des 2025

When macOS gets frostbite. [Research Saturday]

Jaron Bradley, Director of Jamf Threat Labs, is sharing their work on "ChillyHell: A Deep Dive into a Modular macOS Backdoor." Jamf Threat Labs uncovers a newly notarized macOS backdoor called ChillyHell, tied to past UNC4487 activity and disguised as a legitimate applet. The malware showcases robust host profiling, multiple persistence mechanisms, timestomping, and flexible C2 communications over both DNS and HTTP. Its modular design includes reverse shells, payload delivery, self-updates, and a brute-force component targeting user credentials. The research can be found here: ⁠ChillyHell: A Deep Dive into a Modular macOS Backdoor

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(3743)

Nightmare on Windows 11.

Nightmare on Windows 11.

Nightmare Eclipse drops a Kaspersky zero-day. The Financial Stability Board warns frontier AI could threaten the global financial system. Anthropic says it has tightened security. CISA adopts a risk-b...

1 Sep 27min

Let’s kill the kill switch.

Let’s kill the kill switch.

Could an AI kill switch create more problems than it solves? A critical Rails flaw is under active attack. Malicious browser extensions steal cryptocurrency. Fire Ant targets trusted network infrastru...

31 Aug 27min

CyberWire Daily at 10: A decade of emerging threat actors and APTs. [Special Edition]

CyberWire Daily at 10: A decade of emerging threat actors and APTs. [Special Edition]

In this episode, Maria Varmazis and Dave Bittner from N2K Cyberwire get back together to discuss the evolution of advanced persistent threats (APTs), threat actor landscape, attribution changes, and ...

30 Aug 24min

Who let the AI hack? [Research Saturday]

Who let the AI hack? [Research Saturday]

Today we are joined by Crystal Morin, Senior Cybersecurity Strategist, and Michael Clark, Senior Director of Threat Research, at Sysdig, sharing their work on "LLMjacking evolved: Attackers are using ...

29 Aug 23min

The blacklist boomerang.

The blacklist boomerang.

A judge rules the Trump administration illegally labeled Anthropic a national security risk. The White House moves to keep foreign technology out of U.S. power systems. OpenAI rallies a global cyber d...

28 Aug 29min

Meta gets a Meta-sized bill.

Meta gets a Meta-sized bill.

Meta settles. Australian police arrest two alleged TeamPCP members. The White House moves to shore up water utility cybersecurity. ATF reports a major cyber incident. The Navy tells sailors to lock do...

27 Aug 31min

The feds flip the script.

The feds flip the script.

The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies. CISA says more than 100 water systems were targeted in July. Attackers exploit a critical...

26 Aug 32min

CISA is running on empty.

CISA is running on empty.

Lawmakers request an investigation into cuts at CISA. Threat actors actively exploit a Zimbra Collaboration Suite vulnerability. A Chinese AI lab preps release of a powerful open-weight model. A new p...

25 Aug 28min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
aftenpodden-usa
stopp-verden
popradet
nokon-ma-ga
fotballpodden-2
bt-dokumentar-2
lydartikler-fra-aftenposten
rss-espen-lee-usensurert
det-store-bildet
aftenbla-bla
hanna-de-heldige
dine-penger-pengeradet
rss-gukild-johaug
rss-ness
e24-podden
rss-penger-polser-og-politikk
frokostshowet-pa-p5