KeRanger ransomware: Apple Macs hit by malicious software attack for the first time ever

Ransomware is malicious software that hijacks a computer and won’t give its owner access until a fee is paid

Andrew Griffin
Monday 07 March 2016 10:13 GMT
Comments
2012Apple CEO Tim Cook describes new models of the iMac desktop computers during an Apple event in San Jose, California October 23, 2012
2012Apple CEO Tim Cook describes new models of the iMac desktop computers during an Apple event in San Jose, California October 23, 2012 (REUTERS/Robert Galbraith)

Your support helps us to tell the story

From reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines a light on the American women fighting for reproductive rights, we know how important it is to parse out the facts from the messaging.

At such a critical moment in US history, we need reporters on the ground. Your donation allows us to keep sending journalists to speak to both sides of the story.

The Independent is trusted by Americans across the entire political spectrum. And unlike many other quality news outlets, we choose not to lock Americans out of our reporting and analysis with paywalls. We believe quality journalism should be available to everyone, paid for by those who can afford it.

Your support makes all the difference.

Mac users have been hit by “ransomware”, one of the most dangerous and malicious kinds of software, for the first known time.

The newly-discovered “KeRanger” attacks encrypts all of the data on machines that it gains access to, and then forces their owners to pay so that they can re-gain access to the device.

The tools are already hugely popular, generating hundreds of millions of dollars for the cyber-criminals that use them. But KeRanger is the first time that Apple’s computers, which are often more resilient to cyber threats, are known to have been affected.

KeRanger forces people affected by it to pay $400 per computer to get access to their files. As with many such attacks, the hackers actually require payment in Bitcoin, which makes it harder to trace the attackers.

If people don’t pay the charge and don’t get their computers cleaned, they might start losing access to the files installed on them soon. That could happen even if they have knowingly been presented with the ransom demand.

The software made its way onto Apple computers through the Transmission BitTorrent client. That software is used for downloading torrents, but the new release of the software also came with the dangerous files bundled in.

The makers of Transmission released a new version of the software that automatically removes the malware from computers that it’s installed on. It advised users to install the software as soon as possible.

Apple chief attacks FBI probes

Apple told Reuters that it had taken steps to stop the software working. It had revoked a digital certificate that allowed the software to install itself on computers, the company said.

Join our commenting forum

Join thought-provoking conversations, follow other Independent readers and see their replies

Comments

Thank you for registering

Please refresh the page or navigate to another page on the site to be automatically logged inPlease refresh your browser to be logged in