Author Topic: First instance of OS X ransomware found in Transmission  (Read 2141 times)

0 Members and 1 Guest are viewing this topic.

chronovore

  • relapsed dev
  • Senior Member

Vertigo

  • Senior Member
Re: First instance of OS X ransomware found in Transmission
« Reply #1 on: March 07, 2016, 08:58:29 PM »
I had a fake ransonware pop up a few months ago on my mac. I never want to have a taste of the real thing.   :o


chronovore

  • relapsed dev
  • Senior Member
Re: First instance of OS X ransomware found in Transmission
« Reply #2 on: March 07, 2016, 10:31:37 PM »
I had a fake ransonware pop up a few months ago on my mac. I never want to have a taste of the real thing.   :o

At my last job in a US office, someone got bit by this and it locked up the entire machine. It's great to think you're technically capable as a developer and then get completely owned by some Slovakian extortion scheme.

VomKriege

  • Do the moron
  • Senior Member
Re: First instance of OS X ransomware found in Transmission
« Reply #3 on: March 08, 2016, 01:55:46 AM »
Ransomware is one of those things that I would expect to be put much more on the forefront of news. I suspect it doesn't because it reflects poorly on our own certainties of security, big business and the people supposedly enforcing order...
ὕβρις

T-Short

  • hooker strangler
  • Senior Member
Re: First instance of OS X ransomware found in Transmission
« Reply #4 on: March 08, 2016, 03:22:46 AM »
One of my colleagues had a client recently who had a Mac with a Windows VM on it, she opened a ransomware attachment in the VM and had home folder sharing on, so her Mac files got encrypted as well. Ouch.
地平線

Rufus

  • 🙈🙉🙊
  • Senior Member
Re: First instance of OS X ransomware found in Transmission
« Reply #5 on: March 08, 2016, 04:47:52 AM »
http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-ransomware-keranger-infected-transmission-bittorrent-client-installer/

Yikes.

They still don't know how Apple's certification process was bypassed.
Quote
The two KeRanger infected Transmission installers were signed with a legitimate certificate issued by Apple. The developer listed this certificate is a Turkish company with the ID Z7276PX673, which was different from the developer ID used to sign previous versions of the Transmission installer. In the code signing information, we found that these installers were generated and signed on the morning of March 4.
I don't know shit about how this works, but this reads as if the certificate was issued to the wrong company somehow. :doge

T-Short

  • hooker strangler
  • Senior Member
Re: First instance of OS X ransomware found in Transmission
« Reply #6 on: March 08, 2016, 05:36:08 AM »
http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-ransomware-keranger-infected-transmission-bittorrent-client-installer/

Yikes.

They still don't know how Apple's certification process was bypassed.
Quote
The two KeRanger infected Transmission installers were signed with a legitimate certificate issued by Apple. The developer listed this certificate is a Turkish company with the ID Z7276PX673, which was different from the developer ID used to sign previous versions of the Transmission installer. In the code signing information, we found that these installers were generated and signed on the morning of March 4.
I don't know shit about how this works, but this reads as if the certificate was issued to the wrong company somehow. :doge

Naw, the affected installer was signed by a legit Apple Dev cert issued to a turkish company. The question is if that cert was stolen/appropriated by hackers, and how the nasty installer ended up on the official Transmission download site.
地平線

Rufus

  • 🙈🙉🙊
  • Senior Member
Re: First instance of OS X ransomware found in Transmission
« Reply #7 on: March 08, 2016, 06:04:57 AM »
I think I get it now. Made a couple of wrong assumptions.

A Turkish company's cert was misappropriated and used to sign a compromised Transmission installer, which then made its way onto the Transmission homepage. Crafty.

T-Short

  • hooker strangler
  • Senior Member
Re: First instance of OS X ransomware found in Transmission
« Reply #8 on: March 08, 2016, 06:13:51 AM »
I think I get it now. Made a couple of wrong assumptions.

A Turkish company's cert was misappropriated and used to sign a compromised Transmission installer, which then made its way onto the Transmission homepage. Crafty.

Yeah, it's the last part which is kinda creepy. Usually when this happens (XCode Ghost, various "Flash Player" installers), the actual installer is sourced from some place which is not the official supplier. But in this case it was on the official site.
地平線

seagrams hotsauce

  • Senior Member
Re: First instance of OS X ransomware found in Transmission
« Reply #9 on: March 08, 2016, 06:16:30 AM »
Does the ransomware render Time Machine useless?

T-Short

  • hooker strangler
  • Senior Member
Re: First instance of OS X ransomware found in Transmission
« Reply #10 on: March 08, 2016, 07:20:51 AM »
Does the ransomware render Time Machine useless?

AFAIK it tries, if the disk is mounted. Dunno if it makes any effort to run backupd or read com.apple.TimeMachine.plist to try and mount destinations, but if you've got an external drive hooked up and mounted, it will try to encrypt those files as well. Probably just steps through /Volumes/, but I'm not familiar with it (nor do I want to be)
地平線

seagrams hotsauce

  • Senior Member
Re: First instance of OS X ransomware found in Transmission
« Reply #11 on: March 08, 2016, 07:30:04 AM »
That makes sense. I usually just plug in my TM drive to backup a couple of times a week instead of leaving it in.

Either way, in the past my sheer stupidity has lead to me deleting 'important' files enough times that anything I consider remotely valuable exists on three or four different HDs. Still pretty disconcerting that something I use so frequently is so vulnerable though

T-Short

  • hooker strangler
  • Senior Member
Re: First instance of OS X ransomware found in Transmission
« Reply #12 on: March 08, 2016, 07:44:42 AM »
That makes sense. I usually just plug in my TM drive to backup a couple of times a week instead of leaving it in.

Either way, in the past my sheer stupidity has lead to me deleting 'important' files enough times that anything I consider remotely valuable exists on three or four different HDs. Still pretty disconcerting that something I use so frequently is so vulnerable though

Well. Cloud backup is fairly mature these days and quite good especially for mobile devices. Crashplan and BackBlaze are both good.

EDIT: Nothing beats TM for system backups though.
地平線

thisismyusername

  • GunOn™! Apply directly to forehead!
  • Senior Member
Re: First instance of OS X ransomware found in Transmission
« Reply #13 on: March 08, 2016, 11:26:30 AM »
Does the ransomware render Time Machine useless?

If you're Time Machine-ing to the same drive: Yes. If you're backing up to another drive and placing that drive somewhere that the ransomware can't see (AKA: Off the computer that is infected) then no, it won't affect it. It's the same as Bitlocker in a way.