Ransom ware makes its first appearance on the Mac

Macintosh software/hardware discussion and troubleshooting

Moderator: James Steele

Post Reply
User avatar
mikehalloran
Posts: 15205
Joined: Sun Jan 25, 2009 5:08 pm
Primary DAW OS: MacOS
Location: Sillie Con Valley

Ransom ware makes its first appearance on the Mac

Post by mikehalloran »

Transmission, used by millions for file sharing, appears to be the culprit ... this time.

https://www.yahoo.com/tech/apple-users- ... nance.html
DP 11.31; 828mkII FW, micro lite, M4, MTP/AV USB Firmware 2.0.1
2023 Mac Studio M2 8TB, 192GB RAM, OS Sonoma 14.4.1, USB4 8TB external, M-Audio AIR 192|14, Mackie ProFxv3 6/10/12; 2012 MBPs Catalina, Mojave
IK-NI-Izotope-PSP-Garritan-Antares, LogicPro X, Finale 27.4, Dorico 5.2, Notion 6, Overture 5, TwistedWave, DSP-Q 5, SmartScore64 Pro, Toast 20 Pro
User avatar
cuttime
Posts: 4299
Joined: Sun May 15, 2005 10:01 pm
Primary DAW OS: MacOS

Re: Ransom ware makes its first appearance on the Mac

Post by cuttime »

I'm wondering if double checking the installer would prevent installation. For the record, MacUpdate has become a minefield of dicey installers.
828x MacOS 13.6.6 M1 Studio Max 1TB 64G DP11.31
User avatar
Phil O
Posts: 7232
Joined: Thu Jul 28, 2005 10:01 pm
Primary DAW OS: MacOS
Location: Scituate, MA

Re: Ransom ware makes its first appearance on the Mac

Post by Phil O »

Yikes! :shock:
DP 11.23, 2020 M1 Mac Mini [9,1] (16 Gig RAM), Mac Pro 3GHz 8 core [6,1] (16 Gig RAM), OS 14.3.1/11.6.2, Lynx Aurora (n) 8tb, MOTU 8pre-es, MOTU M6, MOTU 828, Apogee Rosetta 800, UAD-2 Satellite, a truckload of outboard gear and plug-ins, and a partridge in a pear tree.
User avatar
billf
Posts: 3662
Joined: Sat Jan 22, 2005 10:01 pm
Primary DAW OS: MacOS
Location: Home

Re: Ransom ware makes its first appearance on the Mac

Post by billf »

cuttime wrote:I'm wondering if double checking the installer would prevent installation. For the record, MacUpdate has become a minefield of dicey installers.
You can try a checksum on it. It's not infallible though.
MacPro5,1 2012, six core 2 x 3.06, 10.12.5, Digital Performer 9.13, 40 gb ram, 828mkIII, 2408 mkII, MTP AV, Logic Pro X 10.3.1, Studio One v 3.2, Pro Tools 12.7.1
User avatar
Gravity Jim
Posts: 2005
Joined: Wed Apr 30, 2008 2:55 am
Primary DAW OS: MacOS
Location: Santa Rosa, CA

Re: Ransom ware makes its first appearance on the Mac

Post by Gravity Jim »

If you're updating a bit torrent client, then you deserve it.
Jim Bordner

MacPro 5,1 (3.33Ghz 12-core), 32g RAM, OS X 10.14.6 • MOTU DP 10.11 • Logic Pro X 10.2.5 • Waves Platinum, UAD-2, Slate Digital, Komplete, Omnisphere 2, LASS, CineSamples, Chipsounds, V Collection 5[color]
User avatar
MIDI Life Crisis
Posts: 26254
Joined: Wed May 18, 2005 10:01 pm
Primary DAW OS: MacOS
Contact:

Re: Ransom ware makes its first appearance on the Mac

Post by MIDI Life Crisis »

Gravity Jim wrote:If you're updating a bit torrent client, then you deserve it.
TOTALLY agree! You effin deserve it! Instant karma.
2013 Mac Pro 32GB RAM

OSX 10.14.6; DP 10; Track 16; Finale 26, iPad Pro, et al

MIDI LIFE CRISIS
User avatar
mikehalloran
Posts: 15205
Joined: Sun Jan 25, 2009 5:08 pm
Primary DAW OS: MacOS
Location: Sillie Con Valley

Re: Ransom ware makes its first appearance on the Mac

Post by mikehalloran »

In 2012, Arturia offered a free MiniMoog VI. It was a pain to download but I noticed that they had a torrent link on the web site. I was in the Opera browser (has a more stable FTP client for downloads that don't work otherwise). What I didn't know was it also had a bittorrent client built in till I clicked on the link and it downloaded quickly.

That was the only time I ever saw a legitimate use for bittorrent client. I have no idea if Opera still has this.
DP 11.31; 828mkII FW, micro lite, M4, MTP/AV USB Firmware 2.0.1
2023 Mac Studio M2 8TB, 192GB RAM, OS Sonoma 14.4.1, USB4 8TB external, M-Audio AIR 192|14, Mackie ProFxv3 6/10/12; 2012 MBPs Catalina, Mojave
IK-NI-Izotope-PSP-Garritan-Antares, LogicPro X, Finale 27.4, Dorico 5.2, Notion 6, Overture 5, TwistedWave, DSP-Q 5, SmartScore64 Pro, Toast 20 Pro
User avatar
mikehalloran
Posts: 15205
Joined: Sun Jan 25, 2009 5:08 pm
Primary DAW OS: MacOS
Location: Sillie Con Valley

Re: Ransom ware makes its first appearance on the Mac

Post by mikehalloran »

What to do if you suspect an infection:

http://researchcenter.paloaltonetworks. ... installer/
DP 11.31; 828mkII FW, micro lite, M4, MTP/AV USB Firmware 2.0.1
2023 Mac Studio M2 8TB, 192GB RAM, OS Sonoma 14.4.1, USB4 8TB external, M-Audio AIR 192|14, Mackie ProFxv3 6/10/12; 2012 MBPs Catalina, Mojave
IK-NI-Izotope-PSP-Garritan-Antares, LogicPro X, Finale 27.4, Dorico 5.2, Notion 6, Overture 5, TwistedWave, DSP-Q 5, SmartScore64 Pro, Toast 20 Pro
User avatar
bayswater
Posts: 11955
Joined: Fri Feb 16, 2007 9:06 pm
Primary DAW OS: MacOS
Location: Vancouver

Re: Ransom ware makes its first appearance on the Mac

Post by bayswater »

mikehalloran wrote:In 2012, Arturia offered a free MiniMoog VI. It was a pain to download but I noticed that they had a torrent link on the web site.
I've seen a few things like this available via BT and wondered why. Maybe it puts less demand on your servers, something to consider if you're offering something for free.
2018 Mini i7 32G 10.14.6, DP 11.3, Mixbus 9, Logic 10.5, Scarlett 18i8
User avatar
cuttime
Posts: 4299
Joined: Sun May 15, 2005 10:01 pm
Primary DAW OS: MacOS

Re: Ransom ware makes its first appearance on the Mac

Post by cuttime »

mikehalloran wrote:What to do if you suspect an infection:

http://researchcenter.paloaltonetworks. ... installer/
Down towards Fig.10 note that the developer is actively working on a way to encrypt Time Machine backups as well.

BTW, I have also seen legit uses of bitTorrent software for distributing public domain, open source, and freeware-not a lot, but they do exist.
828x MacOS 13.6.6 M1 Studio Max 1TB 64G DP11.31
User avatar
mikehalloran
Posts: 15205
Joined: Sun Jan 25, 2009 5:08 pm
Primary DAW OS: MacOS
Location: Sillie Con Valley

Re: Ransom ware makes its first appearance on the Mac

Post by mikehalloran »

cuttime wrote:
mikehalloran wrote:What to do if you suspect an infection:

http://researchcenter.paloaltonetworks. ... installer/
Down towards Fig.10 note that the developer is actively working on a way to encrypt Time Machine backups as well.. . .
Of course. Otherwise, the threat isn't real. Corrupting multiple Time Machine backups over time will prove to be a very difficult task.
DP 11.31; 828mkII FW, micro lite, M4, MTP/AV USB Firmware 2.0.1
2023 Mac Studio M2 8TB, 192GB RAM, OS Sonoma 14.4.1, USB4 8TB external, M-Audio AIR 192|14, Mackie ProFxv3 6/10/12; 2012 MBPs Catalina, Mojave
IK-NI-Izotope-PSP-Garritan-Antares, LogicPro X, Finale 27.4, Dorico 5.2, Notion 6, Overture 5, TwistedWave, DSP-Q 5, SmartScore64 Pro, Toast 20 Pro
User avatar
monkey man
Posts: 13932
Joined: Fri Apr 22, 2005 10:01 pm
Primary DAW OS: MacOS
Location: Melbourne, Australia

Re: Ransom ware makes its first appearance on the Mac

Post by monkey man »

Transmission is the only client I've ever used, and I downloaded the update last Friday only a matter of minutes after Apple (or the Transmission folk - both entities did some stuff) had tagged the installer to not open.

Unaware of the malware thing, I spent the whole day trying to get it to open, running console scripts I didn't understand and wading my way through countless forum threads which might as well have been in Greek. Interestingly, I couldn't understand why Google searches didn't yield exact matches to my issue. Obviously it was because it wasn't long before a kosher update had been posted, making the "issue" obsolete.

If it weren't for the fact that I regularly read the active topics here (even 'though I can't log in, explained elsewhere on the forum), I'd not have known to seek out the relevant info (for edumahcation purposes only) and download the updated installer.

Thank you, Mike, for the extremely-valuable heads-up!

Oh, and Magilla, a link to "30 Sites For Legal (and Free) Torrents":

https://www.google.com.au/url?q=http:// ... I-8LFKlXzw

Also, apart from legit vendors' provision of torrent links for fast, load-spread downloads of their products, some musos, of which I imagine I'll be one one day, actually place their material up as free torrents for promotional purposes. The theory is that more folks may get to learn about your existence and hear your music than might otherwise have been the case. If a portion of this larger-than-otherwise pool of consumers decides it likes your stuff enough, it will choose to pay for it. Heck, even illegal-torrent posters often stress that if the recipients like what they see or hear, they ought to buy the real thing.

All I'm trying to say is that it's not all knives and daggers, something you mightn't have been aware of given your vitriolic response. I, for example, don't agree that I "deserve it". I'm not asking you to dial back that Sicilian passion; perish the thought! Rather, to perhaps re-evaluate that statement.

Oh, and I hope you've been well, matey!

Mac 2012 12C Cheese Grater, OSX 10.13.6
MOTU DP8.07, MachFive 3.2.1, MIDI Express XT, 24I/O
Novation, Yamaha & Roland Synths, Guitar & Bass, Kemper Rack

Pretend I've placed your favourite quote here
User avatar
monkey man
Posts: 13932
Joined: Fri Apr 22, 2005 10:01 pm
Primary DAW OS: MacOS
Location: Melbourne, Australia

Re: Ransom ware makes its first appearance on the Mac

Post by monkey man »

... but wait, there's more:

The free download manager the UVI site recommends, which I've just installed as I was only getting 20-30k a second with Safari for the 9GB Digital-Synsations download, includes... wait for it... torrent-download, upload and browsing ability.

I mention this 'cause it seems to me that the method of distribution is still growing at a pace, as is its adoption for lessening the load on proprietary servers for many sites. Whether you're for the "technology" or not, my guess is that we'll all just have to deal with / get used to it as I can't see it going anywhere in a hurry. When you think about it, it's actually a far more efficient method of distribution, reducing or eliminating altogether the focussed burden on a single server or farm.

Mac 2012 12C Cheese Grater, OSX 10.13.6
MOTU DP8.07, MachFive 3.2.1, MIDI Express XT, 24I/O
Novation, Yamaha & Roland Synths, Guitar & Bass, Kemper Rack

Pretend I've placed your favourite quote here
Post Reply