
- ChillyHell is a modular macOS backdoor created in 2021 that passed Apple’s notarization and stayed undetected for years
- Mandiant spotted it in 2023, but the info wasn’t shared publicly, so AV tools didn’t catch on
- Jamf exposed it in 2025, revealing it’s still notarized and not flagged by antivirus engines
For at least four years, a piece of modular Apple malware was being deployed on target devices, without being flagged by antivirus solutions.