MacRansom - Offered as Ransomware-as-a-Service
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
The malware is said to be developed by former Yahoo and Facebook software engineers who believed they had a knack for creating Mac malware.
According to researchers who analysed a sample of MacRansom, a prompt is displayed informing the user the program is from an unidentified developer. Clicking 'open' in this instance allows the ransomware to run.
Once the malware is initiated, it determines whether it's being run in a non-Mac environment or if it's being debugged. If it's not, the ransomware uses symmetric encryption with a hardcoded key to encrypt user files.
The ransomware demands a ransom paid in Bitcoin (BTC) to decrypt their files but researchers are unclear if the files can in fact be decrypted at all.
Remediation steps
Last edited: 17 February 2020 11:34 am