KeRanger is a macOS ransomware family widely regarded as the first fully functional ransomware observed in the wild targeting OS X/macOS. It emerged in March 2016 and was distributed through a supply-chain compromise of the legitimate Transmission BitTorrent client, whose installer was trojanized and signed with a valid Apple-issued developer certificate, allowing the malware to bypass Gatekeeper protections under default settings. The campaign reportedly infected thousands of Mac users.
After execution via the compromised Transmission application, KeRanger installs and launches a hidden payload, delays activity for several days, then profiles the host and contacts attacker-controlled infrastructure reachable through Tor-related services. It retrieves cryptographic keying material and encrypts victim files using a hybrid encryption scheme involving asymmetric and symmetric cryptography. It targets user data on local systems and mounted volumes, appends a new encrypted-file extension, and drops ransom notes instructing victims to pay for decryption.
KeRanger primarily targets macOS systems and focuses on encrypting a broad range of file types associated with documents, images, archives, source code, databases, certificates, and other user data. It has been described as an early notable macOS ransomware strain and as a variant or rewrite related to Linux.Encoder.1. Apple responded by revoking the abused signing certificate and updating built-in protections, while Transmission replaced the compromised installer with a clean version and issued updates to affected users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
"WannaCry ransomware attack"; "CryptoLocker"; "TeslaCrypt"; "KeRanger"; "Hidden Tear"; "Jigsaw (ransomware)"; "Atlanta government ransomware attack"; "2019 Baltimore ransomware attack"; "FBI MoneyPak Ransomware"; "Annabelle (ransomware)"; "Philadelphia (ransomware)"; "Kirk Ransomware"; "Rensenware"; "Hitler-Ransomware"
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Notable early macOS ransomware focused on file encryption.
Referenced as a historical supply-chain example in which the Transmission installer distributed macOS ransomware.
Referenced as a prior example of macOS ransomware.
Referenced as an example of earlier ransomware targeting macOS/OS X.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.