Candlelites

Everything from Everywhere

new macos ransomware spotted in the wild

new macos ransomware spotted in the wild News Article With The full text news. The Resource Link is down the post and you can View this News Article in the source page.



new macos ransomware spotted in the wild

a new file-encrypting ransomware program for macos is being distributed through bittorrent websites, and users who fall victim to it won’t be able to recover their files, even if they pay. crypto ransomware programs for macos are rare. this is the second such threat found in the wild so far, and it’s a poorly designed one. the program was named osx/filecoder.e by the malware researchers from antivirus vendor eset who found it. osx/filecoder.e masquerades as a cracking tool for commercial software like adobe premiere pro cc and microsoft office for mac and is being distributed as a bittorrent download. it is written in apple’s swift programming language by what appears to be an inexperienced developer, judging from the many mistakes made in its implementation. the application installer is not signed with a developer certificate issued by apple, which makes the malware’s installation harder on recent os x and macos versions, as users would need to override the default security settings. the biggest problem with this malware, though, is the way in which it encrypts files. it generates a single encryption key for all files and then stores the files in encrypted zip archives. however, the malware doesn’t appear to have any ability to communicate with an external server, so the encryption key is never sent to the attacker before being destroyed. this means that even if victims follow the hacker’s instructions (included in a readme!...