OSX/MacRansom is a macOS-targeting ransomware family described as a relatively unsophisticated but notable threat because it targets Macs and was offered as 'Ransomware as a Service' through a TOR-based portal, with customization available via direct contact with the author. It was discovered by Fortinet researchers. The malware performs anti-analysis checks before execution, including anti-debugging via ptrace using the PT_DENY_ATTACH flag and anti-VM checks by running system commands to identify virtualized environments; if these checks fail, it exits. For persistence, it copies itself to ~/Library/.FS_Store and creates a launch agent plist at ~/Library/LaunchAgents/com.apple.finder.plist so it executes at user login if not already running. It waits for a hard-coded trigger date before beginning encryption. To encrypt data, it searches for user files using system commands while excluding itself, then invokes the malware on each discovered file. The encryption routine uses a symmetric algorithm with a static key that is permuted per file rather than RSA. The permutation key is neither stored nor transmitted to the attacker, which makes recovery/decryption nearly impossible once files are encrypted. High-confidence indicators and detection opportunities mentioned in the content include a running '.FS_Store' process and the presence of '~/Library/LaunchAgents/com.apple.finder.plist'. Defensive tooling specifically noted includes BlockBlock, which can detect and block the persistence attempt, and RansomWhere?, which can generically detect and block the encryption activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
OSX/MacRansom is a ransomware targeting macOS systems. It is notable for being offered as Ransomware-as-a-Service (RaaS) and for its use of basic anti-debugging and anti-VM techniques. The malware persists as a launch agent, encrypts user files using a symmetric key that is permuted per file (with the permutation not saved), making decryption without the key practically impossible. It is not technically advanced but is significant as one of the few ransomware families targeting macOS.
OSX/MacRansom is ransomware offered as a service, designed to infect Macs, encrypt files, and demand ransom payments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.