Security News > 2023 > April > LockBit ransomware encryptors found targeting Mac devices
The LockBit ransomware gang has created encryptors targeting Macs for the first time, likely becoming the first major ransomware operation to ever specifically target macOS. The new ransomware encryptors were discovered by cybersecurity researcher MalwareHunterTeam who found a ZIP archive on VirusTotal that contained what appears to be all of the available LockBit encryptors.
Historically, the LockBit operation uses encryptors designed for attacks on Windows, Linux, and VMware ESXi servers.
As shown below, this archive [VirusTotal] also contained previously unknown encryptors for macOS, ARM, FreeBSD, MIPS, and SPARC CPUs.
BleepingComputer analyzed the strings in the LockBit encryptor for Apple M1 and found strings that are out of place in a macOS encryptor, indicating that these were likely haphazardly thrown together in a test.
The good news is that these encryptors are likely not ready for deployment in actual attacks against macOS devices.
Cisco Talos researcher Azim Khodjibaev told BleepingComputer that based on their research, the encryptors were meant as a test and were never intended for deployment in live cyberattacks.
News URL
Related news
- LockBit claims ransomware attack on Fulton County, Georgia (source)
- LockBit ransomware disrupted by global police operation (source)
- LockBit ransomware gang disrupted by global operation (source)
- LockBit Ransomware's Darknet Domains Seized in Global Law Enforcement Raid (source)
- Police arrests LockBit ransomware members, release decryptor in global crackdown (source)
- Police arrest LockBit ransomware members, release decryptor in global crackdown (source)
- LockBit Ransomware Operation Shut Down; Criminals Arrested; Decryption Keys Released (source)
- Cops turn LockBit ransomware gang's countdown timers against them (source)
- US offers $15 million bounty for info on LockBit ransomware gang (source)
- U.S. Offers $15 Million Bounty to Hunt Down LockBit Ransomware Leaders (source)