Menu
New macOS ransomware spotted in the wild

New macOS ransomware spotted in the wild

The program's creator asks for payments but doesn't have the encryption key to unlock victims' files

A new file-encrypting ransomware program for macOS is being distributed through bittorrent websites and users who fall victim to it won't be able to recover their files, even if they pay.

Crypto ransomware programs for macOS are rare. This is the second such threat found in the wild so far, and it's a poorly designed one. The program was named OSX/Filecoder.E by the malware researchers from antivirus vendor ESET who found it.

OSX/Filecoder.E masquerades as a cracking tool for commercial software like Adobe Premiere Pro CC and Microsoft Office for Mac and is being distributed as a bittorrent download. It is written in Apple's Swift programming language by what appears to be an inexperienced developer, judging from the many mistakes made in its implementation.

The application installer is not signed with a developer certificate issued by Apple, which makes the malware's installation harder on recent OS X and macOS versions, as users would need to override the default security settings.

The biggest problem with this malware, though, is the way in which it encrypts files. It generates a single encryption key for all files and then stores the files in encrypted zip archives. However, the malware doesn't appear to have any ability to communicate with an external server, so the encryption key is never sent to the attacker before being destroyed.

This means that even if victims follow the hacker's instructions (included in a README!.txt file left on the computer) on how to pay the ransom, they won't get their files back. The encryption appears to be strong, so it cannot be cracked using alternative means either.

"The random ZIP password is generated with arc4random_uniform which is considered a secure random number generator," the ESET researchers said in a blog post Wednesday. "The key is also too long to brute force in a reasonable amount of time."

The researchers have monitored the bitcoin wallet address used by the attacker and they haven't seen any payment made so far. The publicly accessible mailbox the attacker used also doesn't show signs of communication with potential victims.

Even though OSX/Filecoder.E is likely the work of an inexperienced coder who chose to scam victims rather than build a command-and-control infrastructure to handle key storage and decryption, it does show that macOS is a viable target for ransomware creators. The variety of such malicious programs for this OS is likely to increase as the growing number of ransomware gangs compete for a limited pool of paying victims on other platforms. 


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Events

Why experience is the new battleground for partners

Join us for an exclusive webinar, in association with Hewlett Packard Enterprise and Technology Services Industry Association (TSIA) and learn about the latest industry insights and how technology services continue to evolve to deliver differentiated value, and how partners can be successful in 2021 and beyond.

Featured

Slideshows

Channel kicks 2021 into gear as After Hours returns to Auckland

Channel kicks 2021 into gear as After Hours returns to Auckland

After Hours made a welcome return to the channel social calendar with a bumper crowd of partners, distributors and vendors descending on The Pantry at Park Hyatt in Auckland to kick-start 2021.

Channel kicks 2021 into gear as After Hours returns to Auckland
The Kiwi channel gathers for the 2020 Reseller News Women in ICT Awards

The Kiwi channel gathers for the 2020 Reseller News Women in ICT Awards

Hundreds of leaders from the New Zealand IT industry gathered at the Hilton in Auckland on 17 November to celebrate the finest female talent in the Kiwi channel and recognise the winners of the Reseller News Women in ICT Awards (WIICTA) 2020.

The Kiwi channel gathers for the 2020 Reseller News Women in ICT Awards
Leading female front runners honoured at the 2020 Reseller News Women in ICT Awards

Leading female front runners honoured at the 2020 Reseller News Women in ICT Awards

The leading female front runners of the New Zealand ICT industry joined together for the annual Reseller News Women in ICT Awards event at the Hilton in Auckland, during which hundreds of guests celebrated 13 outstanding individuals who won awards, chosen from more than 50 finalists representing over 30 organisations.

Leading female front runners honoured at the 2020 Reseller News Women in ICT Awards
Show Comments