6 ms·
Apple has shut down the first fully-functional Mac OS X ransomware
- v64 11y agoHas the Transmission team offered any explanation of how the tainted binary ended up being served by them? My concern is that the attackers were also able to maliciously modify the Transmission source code.
- josefdlange 11y agoSomeone compromised their main web server where the binaries are hosted and put up a malicious binary.
- v64 11y agoDo you have a citation for this? The extent of what was illicitly accessed remains unclear. Without knowing how their infrastructure is set up, it's not possible to say that the intrusion was limited to just the web server.
- cshenoy 11y agoHere's the Reuters article where they state that: http://www.reuters.com/article/apple-ransomware-idINL1N16F17Q http://www.reuters.com/article/apple-ransomware-idINL1N16F17...
- v64 11y agoThanks for that, at least it's something. John Clay is listed here[1] as a contributor to "Website maintenance and troubleshooting, Mac OS X help documentation". I wish they would post a similar update on their website and explicitly confirm that the current source and binaries have been audited and are safe. [1] https://github.com/jparyani/Transmission/blob/master/AUTHORS https://github.com/jparyani/Transmission/blob/master/AUTHORS
- redthrowaway 11y agoThey've probably addressed it officially by now, but the malware was only included in v2.9.0 downloaded from the web page directly. It wasn't included if the update was performed through the Transmission client. That would seem to suggest it was the web server that was compromised.
- arthurfm 11y agoApparently [1] the binaries are hosted on the same server as their forums. [1] https://twitter.com/leifnixon/status/706786995029340160 https://twitter.com/leifnixon/status/706786995029340160
- deleted 11y ago[deleted]
- jcoffland 11y ago> The fact that OS X has now been targeted speaks to the popularity of Apple’s operating system It's not a security breach it's a problem of rising popularity. That's one way to spin it.
- weaksauce 11y agoIt is a security breach but in the past most malware has been targeting windows because of the larger financial upside due to popularity. As OS X gets more popular expect more attempts like this.
- jcoffland 11y agoYou don't think it has anything to do with the fact that OSX is more secure than Windows due to the underlying OS being based on FreeBSD? The economics have been in favor of attacking OSX for along time now. Especially when you consider that OSX users likely have more money on average since OSX adoption has been much higher among the affluent.
- astrodust 11y agoThe BSD angle is one component of the security. The other is strictly cultural. OS X users aren't in the habit of clicking "Yeah, whatever, just install" on every dialog that pops up in their face. They're used to just dropping the application into your Applications folder and running it, or downloading it from the App Store. Windows is a wasteland of garbage, of unsigned applications from shady looking sites, where telling the real thing from a malicious fake is often very difficult, even for experienced users. If you're not familiar with the application in question and just Google for it and download the first match you can get burned very badly. This is generally not the case for OS X since the applications tend to be more tightly curated. Consider Panic Software, makers of Transmit, which comes signed by the developer, and Filezilla, which generally comes from Sourceforge. The official site for Transmit is well maintained and offers a no-nonsense download link. For contrast, the official download for Filezilla, an equally popular FTP client for Windows, came with malware bundled in due to SourceForge's bad business decisions. If that isn't a sign of a completely dysfunctional software ecosystem i don't know what is. In the Windows world people are constantly battling this sort of garbage. In the OS X world malware like this is a shocking anomaly.
- nickpsecurity 11y ago"...has shut down the first fully-functional Mac OS X ransomeware" Here I was hoping it was the second malware coded with functional programming. Scheme last time [1]. I was hoping to see some systems Haskell or ATS in there. Oh well. Always another opportunity when it comes to malware. [1] http://philosecurity.org/2009/01/12/interview-with-an-adware-author http://philosecurity.org/2009/01/12/interview-with-an-adware...
- redthrowaway 11y ago>Windows has this thing called Create Remote Thread. Basically, the semantics of Create Remote Thread are: You’re a process, I’m a different process. I call you and say “Hey! I have this bit of code. I’d really like it if you’d run this.” You’d say, “Sure,” because you’re a Windows process– you’re all hippie-like and free love. Windows processes, by the way, are insanely promiscuous. So! We would call a bunch of processes, hand them all a gob of code, and they would all run it. I...wait, what? Did Windows actually used to be that bad?
- 21 11y agoThis still exists, and it's used by lots of extensions. But you can only inject DLLs (this is how it's called) if your process already has some admin rights and if the other process is not of a higher integrity.
- jahewson 11y agoWell, the remote process has to have been launched with the appropriate permissions to allow remote threads. Also the remote thread can only run code which already exists in the remote process, though one common trick is to call LoadLibrary to inject a custom DLL.
- nickpsecurity 11y agoLook up the Shatter Attack.
- chadzawistowski 11y agoI still use this, and authored a tool to inject the .Net runtime and run arbitrary C# code! https://github.com/ChadSki/SharpNeedle https://github.com/ChadSki/SharpNeedle
- zymhan 11y agoSo this confirms that Apple revoking the app-signing certificate that pissed off a bunch of people was related to KeRanger?
- kogir 11y agoNo. They revoked that single developer's certificate. I think you're referring to an Apple certificate that simply expired and invalidated many App Store signatures.
- kolinko 11y agoThey revoked the developer's certificate, or they blocked opening up of an image with a given checksum?
- duskwuff 11y agoBoth. Apple has updated XProtect to detect the malicious Transmission disk image and prevent it from being opened, and has additionally revoked the developer certificate which was used to sign the application on that disk image to prevent any other applications they sign from being treated as trusted.
- wodenokoto 11y agoThat is a poor error message. I would assume apple was trying to block me from using torrents rather than protect me from malware if I saw that error and hadn't kept up with the news.