ESET researchers reported a new macOS crypto-ransomware family, FindZip, that encrypts files on Apple systems and marks a notable expansion of ransomware activity beyond Windows. The malware was observed targeting common user data and demanding payment to restore access, underscoring that macOS users were no longer insulated from file-encrypting extortion campaigns.
The report highlighted that the threat was built to run on macOS and operate as a conventional ransomware infection, locking victims out of their files after execution. The discovery added to evidence that financially motivated attackers were adapting established ransomware tactics to Apple environments, increasing risk for organizations with mixed-platform fleets and reinforcing the need for tested backups, endpoint protection, and user awareness on macOS devices.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
ESET published a report describing a new crypto-ransomware threat affecting macOS systems. The reference provides no additional incident details beyond the existence of the malware and its platform target.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.