'Patcher' ransomware locks macOS files for good

By

Don't pirate software, and back up offline.

A new badly coded ransomware targeting Apple's macOS operating system is currently spreading via pirated software, security researchers have warned.

'Patcher' ransomware locks macOS files for good

Called Patcher, the malware was found by security vendor ESET on BitTorrent peer-to-peer distribution sites.

Patcher is written in Apple's Swift language, and comes hidden in Torrent files for cracked (unlocked) versions of popular paid-for software, specifically Adobe Premiere Pro and Microsoft Office for Mac.

Once activated by a user, the malware not only encrypts files in the /Users directory, but also scrambles data on all mounted and network storage it finds in the /Volumes directory.

The ransomware then asks victims for a payment of 0.25 Bitcoin (A$367) for a decryption key.

However, Patcher is badly coded and lacks the ability to communicate with a command and control server.

This means the key that was generated to encrypt the files on users' computers cannot be sent to the ransomware authors, and they in turn cannot send a decryption key to victims, ESET said.

In other words, paying the ransom will not unlock the files.

"This new crypto-ransomware, designed specifically for macOS, is surely not a masterpiece," ESET said.

"Unfortunately, it’s still effective enough to prevent the victims accessing their own files and could cause serious damage."

ESET recommends users avoid downloading pirated software, and ensure they current, offline backups of their data.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Greater Western Water's billing system data issues laid bare

Greater Western Water's billing system data issues laid bare

Microsoft plans full quantum-resistant cryptography transition by 2033

Microsoft plans full quantum-resistant cryptography transition by 2033

Attackers weaponise Linux file names as malware vectors

Attackers weaponise Linux file names as malware vectors

Log In

  |  Forgot your password?