CHILLYHELL and ZynorRAT malware activity
Malware Activity
Summary
Hide ▲
Show ▼
The discovery of CHILLYHELL and ZynorRAT expands cross-platform malware risk across macOS, Windows, and Linux with backdoor, RAT, persistence, and exfiltration functions. The two families add fresh remote access and command-and-control capability to active malware tooling. CHILLYHELL uses hard-coded C2 infrastructure and stealthy persistence, while ZynorRAT uses a Telegram bot for centralized control. Together, they show continued development of modular malware that can steal data, run commands, and maintain access.
Related Happenings
CrystalRAT Telegram-promoted malware-as-a-service
Malware Activity
H score28
First: 02.04.2026 02:17
Last: 02.04.2026 02:17
Sources 1
About this happening:
The CrystalRAT malware-as-a-service is being promoted on Telegram and YouTube with remote access, data theft, keylogging, and clipboard hijacking, incr...
CrystalRAT Telegram-promoted malware-as-a-service
Malware ActivityAbout this happening: The CrystalRAT malware-as-a-service is being promoted on Telegram and YouTube with remote access, data theft, keylogging, and clipboard hijacking, incr...
Amnesia RAT retrieved from Dropbox for data theft and remote control
Malware Activity
H score29
First: 24.01.2026 13:09
Last: 24.01.2026 13:09
Sources 1
About this happening:
The Amnesia RAT payload is being staged from Dropbox, giving the operators a remote-access trojan that can steal data and control infected endpoints. It is the final s...
Amnesia RAT retrieved from Dropbox for data theft and remote control
Malware ActivityAbout this happening: The Amnesia RAT payload is being staged from Dropbox, giving the operators a remote-access trojan that can steal data and control infected endpoints. It is the final s...
Tsundere botnet expanding on Windows
Malware Activity
H score23
First: 20.11.2025 18:57
Last: 20.11.2025 18:57
Sources 1
About this happening:
The Tsundere botnet is actively expanding against Windows users, and its operators can make infected systems run arbitrary JavaScript from a command-and-control serv...
Tsundere botnet expanding on Windows
Malware ActivityAbout this happening: The Tsundere botnet is actively expanding against Windows users, and its operators can make infected systems run arbitrary JavaScript from a command-and-control serv...
TAMECAT PowerShell backdoor deployment and exfiltration
Malware Activity
H score23
First: 14.11.2025 16:40
Last: 14.11.2025 16:40
Sources 1
About this happening:
TAMECAT is being used as a PowerShell backdoor to maintain persistent access on compromised hosts and move data out through HTTPS, Discord, and Telegram. The malwa...
TAMECAT PowerShell backdoor deployment and exfiltration
Malware ActivityAbout this happening: TAMECAT is being used as a PowerShell backdoor to maintain persistent access on compromised hosts and move data out through HTTPS, Discord, and Telegram. The malwa...
GOVERSHELL multi-variant phishing-delivered malware activity
Malware Activity
H score23
First: 10.11.2025 18:00
Last: 10.11.2025 18:00
Sources 1
About this happening:
The GOVERSHELL malware was observed in five evolving variants, raising the risk of remote command execution and persistent access on infected systems. The payload...
GOVERSHELL multi-variant phishing-delivered malware activity
Malware ActivityAbout this happening: The GOVERSHELL malware was observed in five evolving variants, raising the risk of remote command execution and persistent access on infected systems. The payload...
Timeline
-
10.09.2025 16:04 1 articles · 10mo ago
CHILLYHELL sample uploaded to VirusTotal
Initial DisclosureApple said it discovered a new CHILLYHELL sample uploaded to the VirusTotal malware scanning platform on May 2, 2025.
Show sources
- CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux Systems — thehackernews.com — 10.09.2025 16:04
-
10.09.2025 16:04 1 articles · 10mo ago
ZynorRAT sample submitted to VirusTotal
Initial DisclosureZynorRAT was first submitted to VirusTotal on July 8, 2025. The Go-based RAT targets Windows and Linux and uses a Telegram bot for command-and-control.
Show sources
- CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux Systems — thehackernews.com — 10.09.2025 16:04
-
10.09.2025 16:04 2 articles · 10mo ago
CHILLYHELL and ZynorRAT analysis highlights cross-platform malware capabilities
Technical Analysis UpdateCHILLYHELL was identified as a modular Apple macOS backdoor attributed to UNC4487, with LaunchAgent and LaunchDaemon persistence, shell-profile tampering, hard-coded HTTP or DNS C2, timestomping, reverse shell access, and password-cracking functions. ZynorRAT was identified as a Go-based RAT targeting Windows and Linux, centrally controlled through a Telegram bot, and built for file exfiltration, screenshot capture, persistence, and arbitrary command execution.
Show sources
- CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux Systems — thehackernews.com — 10.09.2025 16:04
- CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux Systems — thehackernews.com — 10.09.2025 16:04