Ransomware found in transmission 2.90

Discussion in 'Mac / Hackintosh' started by statik, Mar 7, 2016.

  1. statik

    statik Audiosexual

    Joined:
    Jul 3, 2014
    Messages:
    1,520
    Likes Received:
    663
    Location:
    under your bed
    Apple Inc (AAPL.O) customers were targeted by hackers over the weekend in the first campaign against Macintosh computers using a pernicious type of software known as ransomware, researchers with Palo Alto Networks Inc (PANW.N) told Reuters on Sunday.
    Ransomware, one of the fastest-growing types of cyber threats, encrypts data on infected machines, then typically asks users to pay ransoms in hard-to-trace digital currencies to get an electronic key so they can retrieve their data.

    Security experts estimate that ransoms total hundreds of millions of dollars a year from such cyber criminals, who typically target users of Microsoft Corp's (MSFT.O) Windows operating system.

    Palo Alto Threat Intelligence Director Ryan Olson said the "KeRanger" malware, which appeared on Friday, was the first functioning ransomware attacking Apple's Mac computers.

    "This is the first one in the wild that is definitely functional, encrypts your files and seeks a ransom," Olson said in a telephone interview.
    Hackers infected Macs through a tainted copy of a popular program known as Transmission, which is used to transfer data through the BitTorrent peer-to-peer file sharing network, Palo Alto said on a blog posted on Sunday afternoon.
    When users downloaded version 2.90 of Transmission, which was released on Friday, their Macs were infected with the ransomware, the blog said.
    An Apple representative said the company had taken steps over the weekend to prevent further infections by revoking a digital certificate that enabled the rogue software to install on Macs. The representative declined to provide other details.

    Transmission responded by removing the malicious version of its software from its website (www.transmissionbt.com). On Sunday it released a version that its website said automatically removes the ransomware from infected Macs.
    The website advised Transmission users to immediately install the new update, version 2.92, if they suspected they might be infected.

    Palo Alto said on its blog that KeRanger is programmed to stay quiet for three days after infecting a computer, then connect to the attacker's server and start encrypting files so they cannot be accessed.
    After encryption is completed, KeRanger demands a ransom of 1 bitcoin, or about $400, the blog said. (bit.ly/1Rvroxv)
    Olson, the Palo Alto threat intelligence director, said that the victims whose machines were compromised but not cleaned up could start losing access to data on Monday, which is three days after the virus was loaded onto Transmission's site.
    Representatives with Transmission could not be reached for comment.

    source
     
    • Interesting Interesting x 2
    • Useful Useful x 1
    • List
  2.  
  3. insaner

    insaner Ultrasonic

    Joined:
    Mar 29, 2015
    Messages:
    161
    Likes Received:
    30
    Lucky i didnt update...
    Often i wait a bit longer.^^
     
  4. Config

    Config Kapellmeister

    Joined:
    Nov 29, 2014
    Messages:
    91
    Likes Received:
    50
    • Like Like x 1
    • Interesting Interesting x 1
    • List
  5. statik

    statik Audiosexual

    Joined:
    Jul 3, 2014
    Messages:
    1,520
    Likes Received:
    663
    Location:
    under your bed
    i did but didnt notice anything, they released 2.92 today which has removal included
     
  6. statik

    statik Audiosexual

    Joined:
    Jul 3, 2014
    Messages:
    1,520
    Likes Received:
    663
    Location:
    under your bed
  7. Config

    Config Kapellmeister

    Joined:
    Nov 29, 2014
    Messages:
    91
    Likes Received:
    50
    • Like Like x 1
    • Interesting Interesting x 1
    • List
  8. NYCGRIFF

    NYCGRIFF Audiosexual

    Joined:
    Jan 15, 2014
    Messages:
    6,982
    Likes Received:
    19,883
    Location:
    New York City
    As Apple products continues its smack down over Microsoft, the tip of the iceberg (regarding such attacks) has begun in earnest. It was only a matter of time. The popularity of all things Apple, is beginning to attract the attention of hackers from all over the globe, and that spells a burgeoning problem. It appears that now Apple and Microsoft are equally at risk. Looks like we're in for a bumpy ride moving forward...
     
    • Like Like x 1
    • Agree Agree x 1
    • List
  9. SineWave

    SineWave Audiosexual

    Joined:
    Sep 4, 2011
    Messages:
    4,326
    Likes Received:
    3,421
    Location:
    Where the sun doesn't shine.
    There is no completely safe OS. Everything can be hacked and cracked, from Windows to NetBSD. It is only a matter of determination. What you can do is use Virtual OS [VirtualBox, VMWare, Parallels] as much as possible - for testing and installing programs as well as for Internet, update programs only when others have already updated without any problems. Don't try to maintain your OS constantly, because you can screw it up easily, newbie or experienced user, it doesn't matter, and you waste precious time on nothing. Play more music, or just simply use the programs more, and stop worrying about the OS and updates until you have a real problem to solve, then update to try solve the problem! :wink: In other words - chillax more! :headbang:
     
  10. Infidel

    Infidel Producer

    Joined:
    Jan 18, 2015
    Messages:
    443
    Likes Received:
    147
    Glad I don't torrent. PITA if you ask me. They never had what I wanted. :dunno:
     
Loading...
Similar Threads - Ransomware found transmission Forum Date
NAS systems by QNAP & Asustor affected by Deadbolt Ransomware Computer Hardware Feb 23, 2022
ThiefQuest ransomware on Mac. Thoughts? Industry News Jul 7, 2020
Beware! New Mac Ransomware On The Scene. Live, Little Snitch, Mixed In Key. Mac / Hackintosh Jul 2, 2020
Ransomware on OSx 10.12 (sierra) Mac / Hackintosh Jun 28, 2020
arturia v collection 6 6.21 r2r ransomware false positve? Software Oct 20, 2018
Loading...