Skip to main content

Update: Mac ransomware may have flaws that allow file recovery

keranger ransomware mac users macbook shot
Seth Schwiet/Unsplash
It’s not exactly a pleasant experience dealing with any sort of malware on your computer, but ransomware — which encrypts users’ files and essentially holds them hostage for payment — ratchets up the malevolence to a whole new level. While until now Windows users have been the primary targets of this type of malware, over the weekend, Mac users found out the hard way that they aren’t safe either.

Over the weekend, security firm Palo Alto Networks discovered that the installers for the torrent client Transmission had been infected with ransomware called KeRanger. Despite the discovery of another piece of ransomware called FileCoder by Kaspersky in 2014, this is the first actual functional ransomware discovered for the Mac.

Updated on 03-09-2016 by Jon Martindale: Added information about the discovery of a possible recovery technique.

Exactly how the Transmission installers were infected with KeRanger isn’t clear. “It’s possible that Transmission’s official website was compromised and the files were replaced by re-compiled malicious versions, but we can’t confirm how this infection occurred,” Palo Alto Networks wrote.

Transmission is signed with a certificate from the developer, so OS X recognizes it as legitimate software, which is how the ransomware manages to infect a system. This certificate was quickly revoked over the weekend, effectively limiting the threat, MacWorld reports. For its part, Transmission is urging users to update to the latest version of the software.

If KeRanger does manage to infect a system, it lies dormant for three days before it strikes. At that point, the user’s files are encrypted, and the malware even attempts to encrypt TimeMachine backups, keeping the user from restoring from a backup. The ransomware then demands 1 bitcoin, roughly $400, to de-encrypt the files.

Should you find yourself infected though, don’t panic — there may be a way out without buying bitcoins first. According to anti-malware company, Bitdefender, the KeRanger ransomware is built upon the foundations of another: Linux.Encoder. While this might not mean much to most, it’s significant because Linux.Encoder is far from flawless.

Researchers at Bitdefender were previously able to create tools to decrypt files, without knowing the private key. Although there’s no guarantee, there’s a possibility that the same solution could be found for KeRanger too.

The prognosis is reasonably strong too, with PCWorld reporting that the KeRanger ransomware is almost identical to the fourth version of Linux.Encoder, which has been countered by BitDefender’s tools. Although no such tool yet exists for KeRanger, it seems likely that it will in the near future.

While ransomware has existed for quite some time, its usage has surged in recent years. One recent variant used the built-in text-to-speech engine in Windows to alert users that their files had been encrypted. And an even scarier incident happened last month, when a hospital was forced to pay $17,000 worth of bitcoin to attackers in order to restore its files.

This particular threat to Mac users may have been short-lived, but this likely won’t be the last time we see ransomware targeting the platform. For the time being, all users can do is try to maintain safe browsing habits, which is often easier said than done.

Kris Wouk
Former Digital Trends Contributor
Kris Wouk is a tech writer, gadget reviewer, blogger, and whatever it's called when someone makes videos for the web. In his…
The Mac just became a true ‘AI PC’
Disney Plus on a MacBook Pro.

Apple has unveiled a significant overhaul of its macOS operating system at its Worldwide Developers Conference (WWDC). The move -- long an expected topic for WWDC -- infuses the Mac with artificial intelligence (AI) across multiple apps, tools, and systems, revamping almost the entire Mac experience in the process. Put together, it has the potential to transform the Mac into an AI PC of the highest order.

Dubbed Apple Intelligence, the new system works across a host of apps -- including third-party ones -- to take them up a level. For example, Apple unveiled tools that can summarize or rewrite text in apps, such as rephrasing an email response for a new context. Apple also showcased some generative AI capabilities similar to those found in rival products like like Midjourney. Apple's spin, though, is that its system has more contextual knowledge. You can ask it to create an image of a friend for their birthday and it will take a photo of them that you have tagged and redesign it in one of several styles. In this case, Apple Intelligence knows who your friend is without you needing to specify a photo first.

Read more
Here’s why people are fearing for the future of this beloved Mac app
bartender app changes ownership mac

Bartender, a popular menu bar customization app for macOS with a long history, was quietly acquired by new developers sometime in the past few months. With no word from the app's original creator or the new owners about the transition, MacUpdater sent out the following alert warning users of the situation.

"The company and developer behind Bartender was replaced in a silent and dubious manner -- updates to version 5.0.52 and newer are your own risk and responsibility."

Read more
Some updates coming to macOS 15 aren’t just about AI
Apple's 15-inch MacBook Air on a desk, with macOS Sonoma running on its display.

Apple's Worldwide Developers Conference (WWDC) is coming up soon, and everyone's expecting a huge announcement around AI. But don't worry, according to a report from AppleInsider, there are some practical tweaks coming to macOS 15 that are in the works. Notably, the System Settings app is set to receive the biggest changes, with other menus and app UIs also expecting some rearranging.

The last update to the Settings app happened with macOS Ventura, changing the name from System Preferences to System Settings and shifting to an iOS-style design, a change that ruffled the feathers of diehard Mac users. This time, the organizational system will reportedly be based on "priority and overall importance."

Read more