LockBit Ransomware Now Targeting Apple macOS Devices

April 18, 2023Rabbi LakshmananEncryption/Malware

LockBit ransomware

The attackers behind the LockBit ransomware operation have developed a new artifact that can encrypt files on devices running Apple’s macOS operating system.

development is report The attack by MalwareHunterTeam over the weekend appears to be the first time a big ransomware crew has created a macOS-based payload.

Additional samples identified by vx-underground A macOS variant has been available since November 11, 2022, indicating that it has previously evaded detection by antimalware engines.

LockBit is a prolific Russian-linked cybercriminal group that has been active since late 2019, and the threat actor has released two major locker updates in 2021 and 2022.

According to statistics released by Malwarebytes last week, LockBit was the second most used ransomware in March 2023 after Cl0p, with 93 successful attacks.

Analysis of the new macOS version (“locker_Apple_M1_64″_) reveals that it relies on invalid signatures to sign executables and is still a work in progress. This also means that even if it is downloaded and launched, it cannot run due to Apple’s gatekeeper protection. on the device.

According to security researcher Patrick Wardle, the payload is packed in files such as autorun.inf and ntuser.dat.log, suggesting the ransomware sample was originally designed to target Windows. It has been.

“Yes, it certainly can run on Apple Silicon, but that’s basically the extent of its impact,” Wardle said. At the place!”

upcoming webinars

Master the Art of Dark Web Intelligence Gathering

Learn the art of extracting threat intelligence from the dark web – join us for this expert-led webinar!

Save my seat!

Wardle also pointed to additional safeguards implemented by Apple such as System Integrity Protection (SIP) and Transparency, Consent, and Control (TCC). These should prevent malicious code execution and require user permission for apps to access protected files and data.

“This means that in the absence of exploits or explicit user authorization, users’ files remain protected,” Wardle points out. “It may still warrant an extra layer or detection/protection.”

Despite the artifact’s overall bugs, the findings clearly show that attackers are increasingly setting their sights on macOS systems.

LockBit officials have since confirmed to Bleeping Computer that a macOS encryption program is “in active development” and the malware likely poses a serious threat to the platform. is showing.

Did you find this article interesting?Please follow us twitter and LinkedIn to read more exclusive content we post.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *