Mac ransomware locks your files and throws away the key (if you’re a pirate)

It’s been an unfortunately busy time for Mac malware over the past couple of weeks, with matters getting worse today as a fresh ransomware threat has been discovered.

The ransomware payload is hidden in a program that goes by the name of Patcher, which is found on torrent sites and claims to be a crack (to get around needing a license key) for a couple of popular software offerings: Adobe Premiere Pro and Microsoft Office for Mac (and possibly others, as well).

ESET, the security outfit which spotted the malware, notes that it’s a crudely coded piece of work. If you fire up the Patcher program, it pops up a dialog box asking you to hit start in order to initiate the cracking process – but if you do so, it’ll proceed to encrypt all your files and demand a ransom payment.

You’ll be asked to fork out 0.25 Bitcoin in order to recover your locked-away data, which is approximately £230 ($290 or AU$370).

But will you get your files back? There’s no guarantee with ransomware, although in this case, the outcome is certain – you most definitely won’t, and paying is in fact pointless.

  • Malware concerns aside, these are the best Macs you can buy

Out of control

ESET observes that this badly written piece of malware doesn’t contain any code whatsoever which would allow it to communicate with a command and control server, so there’s no method of sending the encryption key to the author, and equally no way for them to unlock your files.

The good news is that the Bitcoin wallet specified for payments has nothing in it, meaning nobody has paid up to the criminals behind the malware yet. Fingers crossed that remains the case.

This episode underlines the fact that downloading cracks via torrents is a very risky (and of course illegal) business. Although, despite the apparent crudeness of this effort, there could be a chance of it getting adapted and hidden inside something that looks like legitimate software in the future.

Ransomware is becoming more and more popular due to the simple fact that it allows criminals to potentially make a fast buck, using common methods such as a timer which rushes the victim into paying (threatening to destroy the decryption key for good after a time limit expires).

And evidently macOS is seen as a ripe target, as well as Windows systems. Apple's computers were first hit by ransomware almost a year ago now.

Via: Neowin

TOPICS

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Macs
A mockup of the possible Apple M3 Ultra logo
Performance isn't the only reason you should buy Apple's M3 Ultra Mac Studio - it's reportedly one of the most power-efficient processors too
Mac Studio on a desk
Apple Mac Studio (M3 Ultra): the ultimate creative workstation
Mac Studio from above.
New benchmark suggests Apple's M3 Ultra may not be much faster than the M4 Max - only a minor uplift in multi-core performance
Apple Mac Mini on wood desk
Forget President’s Day sales, Apple is selling an M2 Mac mini refurb for just over $300 which could be the PC bargain of the year
Sergii Figurnyi
Apple's M5 chip is rumored to be in mass production - but we're still waiting for M4 MacBook Airs
A hand holding up the new Mac mini M4
Apple's M4 Mac mini might be one of the best Macs ever, but it has a serious issue that needs fixing right now
Latest in News
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening